|
|
Log in / Subscribe / Register

openstack-glance: authorization bypass

Package(s):openstack-glance CVE #(s):CVE-2016-0757
Created:February 29, 2016 Updated:March 7, 2016
Description: From the Red Hat advisory:

An authorization vulnerability in OpenStack Image service was discovered, which allowed image-status manipulation using locations. By removing the last location of an image, an authenticated user could change the status from 'active' to 'queue'. A malicious tenant could exploit this flaw to silently replace owned image data, regardless of its original creator or visibility settings. Only environments with show_multiple_locations set to true (not default) were affected.

Alerts:
Red Hat RHSA-2016:0358-01 openstack-glance 2016-03-07
Red Hat RHSA-2016:0352-01 openstack-glance 2016-03-03
Red Hat RHSA-2016:0354-01 openstack-glance 2016-03-03
Red Hat RHSA-2016:0309-01 openstack-glance 2016-02-29

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds