The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Essex | Openstack | 2012.1 (including) | 2012.1 (including) |
Folsom | Openstack | 2012.2 (including) | 2012.2 (including) |
Image_registry_and_delivery_service_(glance) | Openstack | - (including) | - (including) |
Glance | Ubuntu | devel | * |
Glance | Ubuntu | quantal | * |
Glance | Ubuntu | upstream | * |