Back

MEDIUM

openstack-glance: unrestricted path traversal flaw

Published Jan 7, 2015

Description

The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.

Affected products

Remediation

Red Hat mitigation

diff --git a/etc/policy.json b/etc/policy.json index 325f00b..a797f12 100644 --- a/etc/policy.json +++ b/etc/policy.json @@ -13,9 +13,9 @@ "download_image": "", "upload_image": "", - "delete_image_location": "", - "get_image_location": "", - "set_image_location": "", + "delete_image_location": "role:admin", + "get_image_location": "role:admin", + "set_image_location": "role:admin", "add_member": "", "delete_member": "",

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 7, 2015
Updated Aug 6, 2024
Reserved Jan 3, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 15, 2014