[openstack-announce] [OSSA-2014-041] Glance v2 API unrestricted path traversal
grant.murphy at hp.com
Tue Dec 23 15:24:57 UTC 2014
OpenStack Security Advisory: 2014-041
Date: December 23, 2014
Title: Glance v2 API unrestricted path traversal
Reporter: Masahito Muroi (NTT)
Versions: up to 2014.1.3 and 2014.2 version up to 2014.2.1
Masahito Muroi from NTT reported a vulnerability in Glance. By setting
a malicious image location an authenticated user can download or delete
any file on the Glance server for which the Glance process user has
access to. Only setups using the Glance V2 API are affected by this flaw.
Kilo (development branch) fix:
* This fix was included in the kilo-1 development milestone and will be included
in future 2014.2.2 (juno) and 2014.1.4 (icehouse) releases.
* The OpenStack VMT recommends revoking all credentials stored in files
accessible by Glance as a precautionary measure.
* A CVE has been requested for this issue, the OpenStack VMT will issue an
errata with the correct CVE number assigned once this information is available.
OpenStack Vulnerability Management Team
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Size: 473 bytes
Desc: not available
More information about the OpenStack-announce