[openstack-announce] [OSSA 2016-006] Glance image status manipulation through locations removal (CVE-2016-0757)
Tristan Cacqueray
tdecacqu at redhat.com
Thu Feb 4 12:43:56 UTC 2016
=================================================================
OSSA-2016-006: Glance image status manipulation through locations
removal
=================================================================
:Date: February 03, 2016
:CVE: CVE-2016-0757
Affects
~~~~~~~
- Glance: <=2015.1.2, >=11.0.0 <= 11.0.1
Description
~~~~~~~~~~~
Erno Kuvaja from HPE reported a vulnerability in Glance. By removing
the last location of an image, an authenticated user may change the
image status back to queued and may be able to upload new image data
resulting in a broken Glance's immutability promise. A malicious
tenant may exploit this flaw to silently replace image data it owns,
regardless of the original creator or the visibility settings. Only
setups with show_multiple_locations enabled (not default) are
affected.
Patches
~~~~~~~
- https://review.openstack.org/275735 (Kilo)
- https://review.openstack.org/275736 (Liberty)
- https://review.openstack.org/275737 (Mitaka)
Credits
~~~~~~~
- Erno Kuvaja from HPE (CVE-2016-0757)
References
~~~~~~~~~~
- https://bugs.launchpad.net/bugs/1525915
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0757
Notes
~~~~~
- This fix will be included in future 2015.1.3 (kilo) and 11.0.2
(liberty) releases.
- The proposed fix prevents the removal of the last location of an
image so that an active image is always available. This action was
previously incorrectly allowed and the fix might break some users who
are relying on the false assumption that it would be ok to replace
the data of existing image in the special case that the multiple
locations has been configured.
--
Tristan Cacqueray
OpenStack Vulnerability Management Team
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 473 bytes
Desc: OpenPGP digital signature
URL: <http://lists.openstack.org/pipermail/openstack-announce/attachments/20160204/1d1e1f8c/attachment.pgp>
More information about the OpenStack-announce
mailing list