Lucene search

K
ubuntuUbuntuUSN-1626-1
HistoryNov 08, 2012 - 12:00 a.m.

Glance vulnerability

2012-11-0800:00:00
ubuntu.com
37

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.004

Percentile

73.3%

Releases

  • Ubuntu 12.10
  • Ubuntu 12.04

Packages

  • glance - OpenStack Image Registry and Delivery Service

Details

Gabe Westmaas discovered that Glance did not always properly enforce access
controls when deleting images. An authenticated user could delete arbitrary
images by using the v1 API under certain circumstances.

OSVersionArchitecturePackageVersionFilename
Ubuntu12.10noarchpython-glance< 2012.2-0ubuntu2.2UNKNOWN
Ubuntu12.10noarchglance< 2012.2-0ubuntu2.2UNKNOWN
Ubuntu12.10noarchglance-api< 2012.2-0ubuntu2.2UNKNOWN
Ubuntu12.10noarchglance-client< 2012.2-0ubuntu2.2UNKNOWN
Ubuntu12.10noarchglance-common< 2012.2-0ubuntu2.2UNKNOWN
Ubuntu12.10noarchglance-registry< 2012.2-0ubuntu2.2UNKNOWN
Ubuntu12.10noarchpython-glance-doc< 2012.2-0ubuntu2.2UNKNOWN
Ubuntu12.04noarchpython-glance< 2012.1.3+stable~20120821-120fcf-0ubuntu1.2UNKNOWN
Ubuntu12.04noarchglance< 2012.1.3+stable~20120821-120fcf-0ubuntu1.2UNKNOWN
Ubuntu12.04noarchglance-api< 2012.1.3+stable~20120821-120fcf-0ubuntu1.2UNKNOWN
Rows per page:
1-10 of 141

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.004

Percentile

73.3%