openstack: glance & ceph conflict which allows image tampering
Published Mar 6, 2023
4.8
MEDIUMCVSS 3.1
EPSS 0.33%
Description
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
Affected products
- Vendor n/a Product OpenStack Defaultn/a
- Version As shipped with Red Hat Openstack 13, 16.1, 16.2, and 17.StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | OpenStack | n/a |
|
No data.
Red Hat OpenStack Platform 13 (Queens)
openstack-glance
Will not fix
Red Hat OpenStack Platform 16.1
openstack-glance
Will not fix
Red Hat OpenStack Platform 16.2
openstack-glance
Fix deferred
Red Hat OpenStack Platform 17.0
openstack-glance
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 13 (Queens) | openstack-glance | Will not fix | n/a |
| Red Hat OpenStack Platform 16.1 | openstack-glance | Will not fix | n/a |
| Red Hat OpenStack Platform 16.2 | openstack-glance | Fix deferred | n/a |
| Red Hat OpenStack Platform 17.0 | openstack-glance | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
You must be using Ceph as a backend to be affected by this flaw. As this flaw would involve significant architectural changes, the impact is moderate. A fix will not be produced for Red Hat OpenStack Platform 16.2 and older releases. If you are concerned about the risk of this flaw against your environment, please follow guidance in the mitigation section, but understand this comes with performance tradeoffs.
Red Hat mitigation
There are two options: 1. Manually disable the show_multiple_locations configuration setting (change it to false). 2. Keep show_multiple_locations enabled, but restrict the glance-api service from being exposed directly to end users. Refer the upstream OSSN listed in the external references section for further details.
References (10)
- https://access.redhat.com/security/cve/CVE-2022-4134 Vendor Advisory
- https://bugs.launchpad.net/glance/+bug/1990157 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=2147462 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0288 Advisory
- https://github.com/advisories/GHSA-5gp5-vxj6-4257 Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/glance/PYSEC-2023-270.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2016-0757
- https://nvd.nist.gov/vuln/detail/CVE-2022-4134
- https://wiki.openstack.org/wiki/OSSN/OSSN-0090 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-4134
Change history (0)
No recorded changes yet.