Lucene search

K
redhatRedHatRHSA-2023:1017
HistoryFeb 28, 2023 - 3:40 p.m.

(RHSA-2023:1017) Important: Red Hat OpenStack Platform 17.0 (openstack-glance) security update

2023-02-2815:40:52
access.redhat.com
13
openstack image service
rest interface
virtual disk images
security fix
cve-2022-47951

CVSS3

5.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

EPSS

0.003

Percentile

66.0%

OpenStack Image Service (code-named Glance) provides
discovery,registration, and delivery services for virtual disk images. The
Image Service API server provides a standard REST interface for querying
information about virtual disk images stored in a variety of back-end
stores, including OpenStack Object Storage. Clients can register new
virtual disk images with the Image Service, query for information on
publicly available disk images, and use the Image Service’s client library
for streaming virtual disk images.

Security Fix(es):

  • Arbitrary file access through custom VMDK flat descriptor
    (CVE-2022-47951)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page listed in the References section.

OSVersionArchitecturePackageVersionFilename
RedHat9noarchopenstack-glance< 22.1.1-0.20220919210603.677c89c.el9ostopenstack-glance-22.1.1-0.20220919210603.677c89c.el9ost.noarch.rpm
RedHat9noarchpython3-glance< 22.1.1-0.20220919210603.677c89c.el9ostpython3-glance-22.1.1-0.20220919210603.677c89c.el9ost.noarch.rpm

CVSS3

5.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

EPSS

0.003

Percentile

66.0%