Lucene search

K
ubuntuUbuntuUSN-1626-2
HistoryNov 09, 2012 - 12:00 a.m.

Glance vulnerability

2012-11-0900:00:00
ubuntu.com
37

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

AI Score

6.5

Confidence

Low

EPSS

0.004

Percentile

73.3%

Releases

  • Ubuntu 12.10

Packages

  • glance - OpenStack Image Registry and Delivery Service

Details

USN-1626-1 fixed vulnerabilities in the v1 API of Glance. This update
provides the corresponding updates for the v2 API.

Original advisory details:

Gabe Westmaas discovered that Glance did not always properly enforce access
controls when deleting images. An authenticated user could delete arbitrary
images by using the v1 API under certain circumstances.

OSVersionArchitecturePackageVersionFilename
Ubuntu12.10noarchpython-glance< 2012.2-0ubuntu2.3UNKNOWN
Ubuntu12.10noarchglance< 2012.2-0ubuntu2.3UNKNOWN
Ubuntu12.10noarchglance-api< 2012.2-0ubuntu2.3UNKNOWN
Ubuntu12.10noarchglance-client< 2012.2-0ubuntu2.3UNKNOWN
Ubuntu12.10noarchglance-common< 2012.2-0ubuntu2.3UNKNOWN
Ubuntu12.10noarchglance-registry< 2012.2-0ubuntu2.3UNKNOWN
Ubuntu12.10noarchpython-glance-doc< 2012.2-0ubuntu2.3UNKNOWN

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

AI Score

6.5

Confidence

Low

EPSS

0.004

Percentile

73.3%