openstack-glance: authorization bypass
| Package(s): | openstack-glance |
CVE #(s): | CVE-2016-0757
|
| Created: | February 29, 2016 |
Updated: | March 7, 2016 |
| Description: |
From the Red Hat advisory:
An authorization vulnerability in OpenStack Image service was discovered,
which allowed image-status manipulation using locations. By removing the
last location of an image, an authenticated user could change the status
from 'active' to 'queue'. A malicious tenant could exploit this flaw to
silently replace owned image data, regardless of its original creator or
visibility settings. Only environments with show_multiple_locations set
to true (not default) were affected. |
| Alerts: |
|