Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery.

Project Subscriptions

Vendors Products
Linux Kernel Subscribe
Opennebula Subscribe
Opennebula Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-40054 Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery.
Fixes

Solution

Upgrade to OpenNebula 6.4.2 EE LTS


Workaround

Set the datastore RESTRICTED_DIRS directive to "/" for any datastores that are mounted on the frontend host.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: blackberry

Published:

Updated: 2024-08-03T10:29:21.020Z

Reserved: 2022-08-05T00:00:00

Link: CVE-2022-37424

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-10-28T16:15:15.970

Modified: 2024-11-21T07:14:58.017

Link: CVE-2022-37424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses