PT-2016-4404 · Openstack+1 · Openstack Image Service+1

Erno Kuvaja

·

Publicado

2016-04-13

·

Atualizado

2023-03-07

·

CVE-2016-0757

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Image Service (Glance) versions prior to 2015.1.3 (kilo) OpenStack Image Service (Glance) versions 11.0.x prior to 11.0.2 (liberty)
Description The issue allows remote authenticated users to tamper with images, potentially compromising the integrity of virtual machines created using these modified images. This is possible when the show multiple locations feature is enabled, allowing attackers to change image status and upload new image data by removing the last location of an image.
Recommendations For OpenStack Image Service (Glance) versions prior to 2015.1.3 (kilo), update to version 2015.1.3 or later. For OpenStack Image Service (Glance) versions 11.0.x prior to 11.0.2 (liberty), update to version 11.0.2 or later. As a temporary workaround, consider disabling the show multiple locations feature until a patch is available.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-0757
GHSA-5GP5-VXJ6-4257
GHSA-5XRJ-GHHP-HX7P
RHSA-2016:0309
RHSA-2016:0352
RHSA-2016:0354
RHSA-2016:0358
USN-3446-1

Produtos afetados

Openstack Image Service
Ubuntu