OpenStack Glance CVE-2012-4573 Arbitrary File Deletion Vulnerability
BID:56437
Info
OpenStack Glance CVE-2012-4573 Arbitrary File Deletion Vulnerability
| Bugtraq ID: | 56437 |
| Class: | Design Error |
| CVE: |
CVE-2012-4573 CVE-2012-5482 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2012 12:00AM |
| Updated: | Apr 13 2015 10:24PM |
| Credit: | Gabe Westmaas from Rackspace |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.10 i386 Ubuntu Ubuntu Linux 12.10 amd64 SuSE Cloud 1.0 Redhat OpenStack Essex 0 OpenStack Glance Folsom 2012.2 OpenStack Glance Essex 2012.1 |
| Not Vulnerable: | |
Discussion
OpenStack Glance CVE-2012-4573 Arbitrary File Deletion Vulnerability
OpenStack Glance is prone to an arbitrary file-deletion vulnerability.
Successful exploits may allow an attacker to delete image files; this may aid in launching further attacks.
http://drupal.org/node/207891
OpenStack Glance is prone to an arbitrary file-deletion vulnerability.
Successful exploits may allow an attacker to delete image files; this may aid in launching further attacks.
http://drupal.org/node/207891
Exploit / POC
OpenStack Glance CVE-2012-4573 Arbitrary File Deletion Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
OpenStack Glance CVE-2012-4573 Arbitrary File Deletion Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
OpenStack Glance CVE-2012-4573 Arbitrary File Deletion Vulnerability
References:
References:
- [OSSA 2012-017] Authentication bypass for image deletion (CVE-2012-4573) (oss-security)
- Authentication bypass for image deletion (CVE-2012-4573, CVE-2012-5 ( Russell Bryant)
- Change Icf2f117a: Ensure image owned by user before delayed_deletion (OpenStack)
- Delete from store after registry delete. (GitHub)
- Non-admin users can cause public glance images to be deleted from the backend st (OpenStack)
- OpenStack Image Registry and Delivery Service (Glance) HomePage (OpenStack)
- SUSE-SU-2012:1455-1: important: Security update for openstack-glance (SUSE)
- RHSA-2012:1558: Security Advisory Low: openstack-glance security update (Red Hat)