[Secure-testing-team] Bug#775926: CVE-2015-1195: Glance still allows users to download and delete any file in glance-api server
Thomas Goirand
zigo at debian.org
Wed Jan 21 16:15:25 UTC 2015
Package: glance
Version: 2014.1.3-10
Severity: critical
Tags: security patch
Title: Glance v2 API unrestricted path traversal through filesystem://
scheme
Reporter: Jin Liu (EMC)
Products: Glance
Versions: up to 2014.1.3 and 2014.2 versions up to 2014.2.1
Description:
Jin Liu from EMC reported that path traversal vulnerabilities in Glance
were not fully patched in OSSA 2014-041. By setting a malicious image
location to a filesystem:// scheme an authenticated user can still
download or delete any file on the Glance server for which the Glance
process user has access to. Only setups using the Glance V2 API are
affected by this flaw.
Kilo (development branch) fix:
https://review.openstack.org/145640
Juno fix:
https://review.openstack.org/145916
Icehouse fix:
https://review.openstack.org/145974
More information about the Secure-testing-team
mailing list