OSSA-2015-019: Glance image status manipulation

OSSA-2015-019: Glance image status manipulation

Date:September 22, 2015
CVE:CVE-2015-5251

Affects

  • Glance: <=2014.2.3, >=2015.1.0, <=2015.1.1

Description

Hemanth Makkapati of Rackspace reported a vulnerability in Glance. By submitting a HTTP PUT request with a “x-image-meta-status” header, a tenant can manipulate the status of their images. A malicious tenant may exploit this flaw to reactivate disabled images, bypass storage quotas and in some cases replace image contents. Setups using the Glance v1 API allow the illegal modification of image status. Setups which also use the v2 API may allow a subsequent re-upload of image contents.

Credits

  • Hemanth Makkapati from Rackspace (CVE-2015-5251)

Notes

  • This fix will be included in future 2014.2.4 (juno) and 2015.1.2 (kilo) releases.
Creative Commons Attribution 3.0 License

Except where otherwise noted, this document is licensed under Creative Commons Attribution 3.0 License. See all OpenStack Legal Documents.