OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Image_registry_and_delivery_service_(glance) | Openstack | * | 2014.2.3 (including) |
Image_registry_and_delivery_service_(glance) | Openstack | 2015.1.0 (including) | 2015.1.0 (including) |
Image_registry_and_delivery_service_(glance) | Openstack | 2015.1.1 (including) | 2015.1.1 (including) |
Glance | Ubuntu | precise | * |
Glance | Ubuntu | trusty | * |
Glance | Ubuntu | upstream | * |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | RedHat | openstack-glance-0:2014.1.5-3.el6ost | * |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | RedHat | openstack-glance-0:2014.1.5-3.el7ost | * |
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | RedHat | openstack-glance-0:2014.2.3-3.el7ost | * |
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | RedHat | openstack-glance-0:2015.1.1-3.el7ost | * |