USN-2208-1: OpenStack Cinder vulnerability
06 May 2014
OpenStack Cinder could be made to expose sensitive information over the network.
- cinder - OpenStack storage service
JuanFra Rodriguez Cardoso discovered that OpenStack Cinder did not enforce
SSL connections when Nova was configured to use QPid and qpid_protocol is
set to 'ssl'. If a remote attacker were able to perform a man-in-the-middle
attack, this flaw could be exploited to view sensitive information. Ubuntu
does not use QPid with Nova by default.