PT-2016-4404 · Openstack+1 · Openstack Image Service+1
Erno Kuvaja
·
Published
2016-04-13
·
Updated
2023-03-07
·
CVE-2016-0757
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Image Service (Glance) versions prior to 2015.1.3 (kilo)
OpenStack Image Service (Glance) versions 11.0.x prior to 11.0.2 (liberty)
Description
The issue allows remote authenticated users to tamper with images, potentially compromising the integrity of virtual machines created using these modified images. This is possible when the
show multiple locations feature is enabled, allowing attackers to change image status and upload new image data by removing the last location of an image.Recommendations
For OpenStack Image Service (Glance) versions prior to 2015.1.3 (kilo), update to version 2015.1.3 or later.
For OpenStack Image Service (Glance) versions 11.0.x prior to 11.0.2 (liberty), update to version 11.0.2 or later.
As a temporary workaround, consider disabling the
show multiple locations feature until a patch is available.Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openstack Image Service
Ubuntu