PT-2015-6790 · Openstack · Openstack Image Service

Eharney

+1

·

Published

2015-08-19

·

Updated

2023-02-13

·

CVE-2015-5163

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenStack Image Service (Glance) versions 2015.1.x before 2015.1.2 (kilo)
Description The issue allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image when using the V2 API.
Recommendations For OpenStack Image Service (Glance) versions 2015.1.x before 2015.1.2 (kilo), update to version 2015.1.2 or later to resolve the issue.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2015-5163
GHSA-Q73F-VJC2-3GQF
PYSEC-2015-39
RHSA-2015:1639

Affected Products

Openstack Image Service