Hemanth Makkapati discovered that OpenStack Glance incorrectly handled access restrictions. A remote authenticated user could use this issue to change the status of images, contrary to access restrictions. (CVE-2015-5251)
Mike Fedosin and Alexei Galkin discovered that OpenStack Glance incorrectly handled the storage quota. A remote authenticated user could use this issue to consume disk resources, leading to a denial of service. (CVE-2015-5286)
Erno Kuvaja discovered that OpenStack Glance incorrectly handled the showmultiplelocations option. When showmultiplelocations is enabled, a remote authenticated user could change an image status and upload new image data. (CVE-2016-0757)
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1:2014.1.5-0ubuntu1.1", "binary_name": "glance" }, { "binary_version": "1:2014.1.5-0ubuntu1.1", "binary_name": "glance-api" }, { "binary_version": "1:2014.1.5-0ubuntu1.1", "binary_name": "glance-common" }, { "binary_version": "1:2014.1.5-0ubuntu1.1", "binary_name": "glance-registry" }, { "binary_version": "1:2014.1.5-0ubuntu1.1", "binary_name": "python-glance" }, { "binary_version": "1:2014.1.5-0ubuntu1.1", "binary_name": "python-glance-doc" } ] }