CVE Vulnerabilities

CVE-2015-5251

Published: Oct 26, 2015 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:P
RedHat/V2
6 MODERATE
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW

OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*.

Affected Software

Name Vendor Start Version End Version
Image_registry_and_delivery_service_(glance) Openstack * 2014.2.3 (including)
Image_registry_and_delivery_service_(glance) Openstack 2015.1.0 (including) 2015.1.0 (including)
Image_registry_and_delivery_service_(glance) Openstack 2015.1.1 (including) 2015.1.1 (including)
Glance Ubuntu precise *
Glance Ubuntu trusty *
Glance Ubuntu upstream *
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 RedHat openstack-glance-0:2014.1.5-3.el6ost *
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 RedHat openstack-glance-0:2014.1.5-3.el7ost *
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 RedHat openstack-glance-0:2014.2.3-3.el7ost *
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 RedHat openstack-glance-0:2015.1.1-3.el7ost *

References