A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality.
https://thehackernews.com/2023/06/urgent-security-updates-cisco-and.html
https://security.openstack.org/ossa/OSSA-2023-003.html
https://lists.debian.org/debian-lts-announce/2024/09/msg00015.html