CVE-2023-2088

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/05/2023
Last modified:
04/11/2025

Description

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:openstack:-:*:*:*:*:*:*:*