The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openstack | Redhat | 4.0 (including) | 4.0 (including) |
Openstack | Redhat | 5.0 (including) | 5.0 (including) |
OpenStack 4 for RHEL 6 | RedHat | openstack-glance-0:2013.2.4-3.el6ost | * |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | RedHat | openstack-glance-0:2014.1.3-4.el6ost | * |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | RedHat | openstack-glance-0:2014.1.3-4.el7ost | * |
Glance | Ubuntu | trusty | * |