openstack-nova: Host file disclosure through qcow2 backing file
Published Jan 15, 2020
No CVSS score
EPSS 0.24%
Description
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not an exploitable issue. Notes: none.
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)
openstack-nova
Will not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)
openstack-nova
Will not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)
openstack-nova
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | openstack-nova | Will not fix | n/a |
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | openstack-nova | Will not fix | n/a |
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | openstack-nova | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has rated this issue as having Low security impact in all supported versions of Red Hat Enterprise Linux OpenStack Platform. While this issue is present, we do not believe the code path is currently reachable in an attacker exploitable fashion. A future update may address this flaw.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Feb 14, 2025.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
No CWE recorded.
References (4)
- https://access.redhat.com/security/cve/CVE-2015-1850 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1231816 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2015-1850
- https://www.cve.org/CVERecord?id=CVE-2015-1850
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2015-1850 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1231816 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2015-1850 | ||
| https://www.cve.org/CVERecord?id=CVE-2015-1850 |
Change history (0)
No recorded changes yet.