GHSA-r4v4-w9pv-6fph · Severity: high · Ecosystem: pip — OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.
Conclusion & alert: CVE-2024-32498 is rated Moderate Risk (45/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.83%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.21% | 0.83% | +0.61% |
| 2 | 2025-12-16 | 0.11% | 0.21% | +0.11% |
| 3 | 2025-11-21 | — | 0.11% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-r4v4-w9pv-6fph · Severity: high · Ecosystem: pip — OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2024-32498 not yet assigned priority: Debian including 3 source packages (cinder, glance, nova), 15 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 15. | https://security-tracker.debian.org/tracker/CVE-2024-32498 |
redhat
|
critical | — | https://access.redhat.com/security/cve/CVE-2024-32498 |
ubuntu
|
medium | CVE-2024-32498 medium priority: Ubuntu including 3 source packages (cinder, glance, nova), 30 status rows across 10 suites (bionic, focal, jammy, mantic, noble, oracular, plucky, questing, upstream, xenial): released 21, needs-triage 7, needed 2. | https://ubuntu.com/security/CVE-2024-32498 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| openstack | cinder | < 22.1.3 | cpe:2.3:a:openstack:cinder:*:*:*:*:*:*:*:* |
| openstack | cinder | >= 23.0.0, < 23.1.1 | cpe:2.3:a:openstack:cinder:*:*:*:*:*:*:*:* |
| openstack | cinder | 24.0.0 | cpe:2.3:a:openstack:cinder:24.0.0:*:*:*:*:*:*:* |
| openstack | glance | < 26.0.1 | cpe:2.3:a:openstack:glance:*:*:*:*:*:*:*:* |
| openstack | glance | >= 28.0.0, < 28.0.2 | cpe:2.3:a:openstack:glance:*:*:*:*:*:*:*:* |
| openstack | glance | 27.0.0 | cpe:2.3:a:openstack:glance:27.0.0:*:*:*:*:*:*:* |
| openstack | nova | < 27.3.1 | cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* |
| openstack | nova | >= 28.0.0, < 28.1.1 | cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* |
| openstack | nova | >= 29.0.0, < 29.0.3 | cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* |