CVE-2024-40767: Openstack Nova

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.

Affected products

  • Openstack Nova: before 27.4.1 (fixed in 27.4.1); from 28.0.0, before 28.2.1 (fixed in 28.2.1); from 29.0.0, before 29.1.1 (fixed in 29.1.1)

Published 2024-07-24. Last modified 2026-06-17.