CVE-2015-7548: Openstack Nova
Low severity, CVSS 3.5. EPSS: 1.8% chance of exploitation in the next 30 days.
OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot.
Affected products
- Openstack Nova: from 12.0.0, before 12.0.1 (fixed in 12.0.1); from 2015.1.0, before 2015.1.3 (fixed in 2015.1.3)
Published 2016-01-12. Last modified 2026-06-17.