Back

MEDIUM

openstack-glance: API v1 copy_from reveals network details

Published Mar 21, 2017

Description

An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'http://localhost:22'. This could then allow an attacker to enumerate internal network details while appearing masked, since the scan would appear to originate from the Glance Image service.

Affected products

Remediation

Red Hat statement

Because the Image Service APIv1 was deprecated in Newton and because a workaround is possible, no fix is being made available. For impacted products and the recommended mitigation, see the Knowledge Base article for this issue: https://access.redhat.com/security/vulnerabilities/2999581

Metrics

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 21, 2017
Updated Aug 5, 2024
Reserved Mar 20, 2017
NVD
Status Analyzed
Modified Sep 17, 2026
Red Hat
Severity Moderate
Public date Mar 15, 2017
GHSA-J6MR-CM6X-H6JG