Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 561194 (CVE-2015-5251) - <app-admin/glance-2015.1.1-r2: Glance v1 API image status manipulation (CVE-2015-5251)
Summary: <app-admin/glance-2015.1.1-r2: Glance v1 API image status manipulation (CVE-2...
Status: RESOLVED FIXED
Alias: CVE-2015-5251
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://bugs.launchpad.net/glance/+bu...
Whiteboard: B4 [noglsa/cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-09-22 17:48 UTC by Matthew Thode ( prometheanfire )
Modified: 2015-09-27 03:06 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2015-09-22 17:48:04 UTC
Hemanth Makkapati of Rackspace reported a vulnerability in
Glance. By submitting a HTTP PUT request with a
'x-image-meta-status' header, a tenant can manipulate the
status of their images. A malicious tenant may exploit this
flaw to reactivate disabled images, bypass storage quotas and
in some cases replace image contents. Setups using the Glance
v1 API allow the illegal modification of image status. Setups
which also use the v2 API may allow a subsequent re-upload of
image contents.

Reproducible: Always
Comment 1 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2015-09-22 17:48:47 UTC
arches, please stablize the following

=app-admin/glance-2015.1.1-r2
Comment 2 Agostino Sarubbo gentoo-dev 2015-09-23 10:02:45 UTC
amd64 stable
Comment 3 Agostino Sarubbo gentoo-dev 2015-09-23 10:03:57 UTC
x86 stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 4 Yury German Gentoo Infrastructure gentoo-dev 2015-09-23 10:49:45 UTC
GLSA Vote: No
Comment 5 Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-09-23 11:16:58 UTC
GLSA Vote: No
Comment 6 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2015-09-24 00:29:37 UTC
cleaned up
Comment 7 Yury German Gentoo Infrastructure gentoo-dev 2015-09-27 03:06:43 UTC
Maintainer(s), Thank you for you for cleanup.

Thank you all. Closing as noglsa.