The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.
{
"binaries": [
{
"binary_version": "2:12.0.0-0ubuntu2",
"binary_name": "glance"
},
{
"binary_version": "2:12.0.0-0ubuntu2",
"binary_name": "glance-api"
},
{
"binary_version": "2:12.0.0-0ubuntu2",
"binary_name": "glance-common"
},
{
"binary_version": "2:12.0.0-0ubuntu2",
"binary_name": "glance-glare"
},
{
"binary_version": "2:12.0.0-0ubuntu2",
"binary_name": "glance-registry"
},
{
"binary_version": "2:12.0.0-0ubuntu2",
"binary_name": "python-glance"
},
{
"binary_version": "2:12.0.0-0ubuntu2",
"binary_name": "python-glance-doc"
}
],
"availability": "No subscription required"
}