Bug 913645 (CVE-2015-1195) - VUL-0: CVE-2015-1195: openstack-glance: Glance v2 API unrestricted path traversal through filesystem:// scheme
Summary: VUL-0: CVE-2015-1195: openstack-glance: Glance v2 API unrestricted path trav...
Status: RESOLVED FIXED
Alias: CVE-2015-1195
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Deadline: 2015-03-11
Assignee: Bernhard Wiedemann
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/112769/
Whiteboard: maint:running:60917:important CVSSv2:...
Keywords:
Depends on:
Blocks:
 
Reported: 2015-01-19 09:52 UTC by Victor Pereira
Modified: 2016-04-27 18:59 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2015-01-19 09:52:50 UTC
CVE-2015-1195

 Affects
 ~~~~~~~
 - Glance: up to 2014.1.3 and 2014.2 versions up to 2014.2.1


 Description
 ~~~~~~~~~~~
 Jin Liu from EMC reported that path traversal vulnerabilities in
 Glance were not fully patched in OSSA 2014-041. By setting a malicious
 image location to a filesystem:// scheme an authenticated user can
 still download or delete any file on the Glance server for which the
 Glance process user has access to. Only setups using the Glance V2 API
 are affected by this flaw.


 Patches
 ~~~~~~~
 - https://review.openstack.org/145974 (Icehouse)
 - https://review.openstack.org/145916 (Juno)
 - https://review.openstack.org/145640 (Kilo)


 Credits
 ~~~~~~~
 - Jin Liu from EMC


 Notes
 ~~~~~
 - This fix was included in the kilo-1 development milestone and will be
  included in future 2014.2.2 (juno) and 2014.1.4 (icehouse) releases.
 - The OpenStack VMT recommends revoking all credentials stored in files
  accessible by Glance as a precautionary measure.
 - A CVE has been requested for this issue, the OpenStack VMT will issue an
  errata with the correct CVE number assigned once this information is
  available.


References:
https://launchpad.net/bugs/1408663
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-1195
http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1195.html
Comment 1 Swamp Workflow Management 2015-01-19 23:02:36 UTC
bugbot adjusting priority
Comment 2 Bernhard Wiedemann 2015-01-21 13:26:10 UTC
fix is in the pipeline for Icehouse and Juno
except for Havana / SUSE-Cloud 3 that would need conflict resolving
(if it is affected)
Comment 7 Swamp Workflow Management 2015-03-04 15:29:24 UTC
An update workflow for this issue was started.
This issue was rated as important.
Please submit fixed packages until 2015-03-11.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/60917