Back

MEDIUM

openstack: glance & ceph conflict which allows image tampering

Published Mar 6, 2023

Description

A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.

Affected products

Remediation

Red Hat statement

You must be using Ceph as a backend to be affected by this flaw. As this flaw would involve significant architectural changes, the impact is moderate. A fix will not be produced for Red Hat OpenStack Platform 16.2 and older releases. If you are concerned about the risk of this flaw against your environment, please follow guidance in the mitigation section, but understand this comes with performance tradeoffs.

Red Hat mitigation

There are two options: 1. Manually disable the show_multiple_locations configuration setting (change it to false). 2. Keep show_multiple_locations enabled, but restrict the glance-api service from being exposed directly to end users. Refer the upstream OSSN listed in the external references section for further details.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 6, 2023
Updated Mar 6, 2025
Reserved Nov 23, 2022
CISA Vulnrichment
Updated Mar 6, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 14, 2022
ENISA EUVD
Assigner redhat
Published Mar 6, 2023
Updated Mar 6, 2025
Exploited since n/a
EUVD-2023-0288 GHSA-5GP5-VXJ6-4257