CVE-2015-5163
openstack-glance: Glance v2 API host file disclosure through qcow2 backing file
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image.
Vulnerabilidad en la acción de importar tareas en OpenStack Image Service (Glance) 2015.1.x en versiones anteriores a 2015.1.2 (kilo), cuando se usa la API V2, permite a usuarios remotos autenticados leer archivos arbitrarios a través de un archivo de respaldo manipulado para una imagen qcow2.
A flaw was found in the OpenStack Image Service (glance) import task action. When processing a malicious qcow2 header, glance could be tricked into reading an arbitrary file from the glance host. Only setups using the glance V2 API are affected by this flaw.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-07-01 CVE Reserved
- 2015-08-18 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-454: External Initialization of Trusted Variables or Data Stores
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://lists.openstack.org/pipermail/openstack-announce/2015-August/000527.html | Mailing List | |
http://www.securityfocus.com/bid/76346 | Vdb Entry | |
https://bugs.launchpad.net/glance/+bug/1471912 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2015-1639.html | 2023-02-13 | |
https://access.redhat.com/security/cve/CVE-2015-5163 | 2015-08-18 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1252378 | 2015-08-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openstack Search vendor "Openstack" | Glance Search vendor "Openstack" for product "Glance" | 2015.1.0 Search vendor "Openstack" for product "Glance" and version "2015.1.0" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Glance Search vendor "Openstack" for product "Glance" | 2015.1.1 Search vendor "Openstack" for product "Glance" and version "2015.1.1" | - |
Affected
|