Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 561194 (CVE-2015-5251)

Summary: <app-admin/glance-2015.1.1-r2: Glance v1 API image status manipulation (CVE-2015-5251)
Product: Gentoo Security Reporter: Matthew Thode ( prometheanfire ) <prometheanfire>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://bugs.launchpad.net/glance/+bug/1482371
Whiteboard: B4 [noglsa/cve]
Package list:
Runtime testing required: ---

Description Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2015-09-22 17:48:04 UTC
Hemanth Makkapati of Rackspace reported a vulnerability in
Glance. By submitting a HTTP PUT request with a
'x-image-meta-status' header, a tenant can manipulate the
status of their images. A malicious tenant may exploit this
flaw to reactivate disabled images, bypass storage quotas and
in some cases replace image contents. Setups using the Glance
v1 API allow the illegal modification of image status. Setups
which also use the v2 API may allow a subsequent re-upload of
image contents.

Reproducible: Always
Comment 1 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2015-09-22 17:48:47 UTC
arches, please stablize the following

=app-admin/glance-2015.1.1-r2
Comment 2 Agostino Sarubbo gentoo-dev 2015-09-23 10:02:45 UTC
amd64 stable
Comment 3 Agostino Sarubbo gentoo-dev 2015-09-23 10:03:57 UTC
x86 stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 4 Yury German Gentoo Infrastructure gentoo-dev 2015-09-23 10:49:45 UTC
GLSA Vote: No
Comment 5 Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-09-23 11:16:58 UTC
GLSA Vote: No
Comment 6 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2015-09-24 00:29:37 UTC
cleaned up
Comment 7 Yury German Gentoo Infrastructure gentoo-dev 2015-09-27 03:06:43 UTC
Maintainer(s), Thank you for you for cleanup.

Thank you all. Closing as noglsa.