CVE-2023-2088: Red Hat Openstack

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.

Affected products

  • Red Hat Openstack: affected versions not specified

Published 2023-05-12. Last modified 2026-06-17.