The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Essex | Openstack | 2012.1 (including) | 2012.1 (including) |
Folsom | Openstack | 2012.2 (including) | 2012.2 (including) |
Image_registry_and_delivery_service_(glance) | Openstack | - (including) | - (including) |
Glance | Ubuntu | natty | * |
Glance | Ubuntu | precise | * |
Glance | Ubuntu | quantal | * |
OpenStack Essex for RHEL 6 | RedHat | openstack-glance-0:2012.1.2-2.el6 | * |