PT-2012-5483 · Openstack · Openstack Glance
Gabe Westmaas
·
Published
2012-11-11
·
Updated
2022-05-17
·
CVE-2012-4573
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenStack Glance versions 2012.1 through 2012.2
Description
The issue allows remote authenticated users to delete arbitrary non-protected images via an image deletion request to the
v1 API endpoint.Recommendations
For versions 2012.1 and 2012.2, consider restricting access to the
v1 API endpoint to prevent unauthorized image deletion until a fix is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Glance