Bugzilla – Bug 947735
VUL-0: CVE-2015-5286: openstack-glance: Glance storage overrun
Last modified: 2016-04-27 19:46:14 UTC
Created attachment 649210 [details] patch for juno
Created attachment 649211 [details] patch for kilo
bugbot adjusting priority
CRD: 2015-10-01 15:00 UTC
The issue is public at https://bugs.launchpad.net/glance/+bug/1498163 information type: Private Security → Public Security summary: - Glance storage quota bypass when token is expired (CVE-2015-5286) + [OSSA 2015-020] Glance storage quota bypass when token is expired + (CVE-2015-5286) Note the updated set of patches.
Created attachment 649799 [details] test_images.py Public exploit from https://bugs.launchpad.net/glance/+bug/1498163/comments/1
Created attachment 649800 [details] test_images_v2.py public exploit from https://bugs.launchpad.net/glance/+bug/1498163/comments/2
public announcement: ===================================== OSSA-2015-020: Glance storage overrun ===================================== :Date: October 01, 2015 :CVE: CVE-2015-5286 Affects ~~~~~~~ - Glance: <=2014.2.3, >=2015.1.0, <=2015.1.1 Description ~~~~~~~~~~~ Mike Fedosin and Alexei Galkin from Mirantis reported a vulnerability in Glance. By deleting images that are being uploaded using a token that is about to expire, a malicious user can overcome the storage quota and accumulate untracked image data in the backend resulting in potential resource exhaustion and denial of service. All Glance setups using the V1 API are affected and all setups using the V2 API with the registry db_api enabled are affected. Patches ~~~~~~~ - https://review.openstack.org/229946 (Juno) - https://review.openstack.org/229975 (Juno) - https://review.openstack.org/229945 (Kilo) - https://review.openstack.org/229973 (Kilo) - https://review.openstack.org/230056 (Liberty) - https://review.openstack.org/229972 (Liberty) - https://review.openstack.org/229943 (Mitaka) - https://review.openstack.org/229971 (Mitaka) Credits ~~~~~~~ - Mike Fedosin from Mirantis (CVE-2015-5286) - Alexei Galkin from Mirantis (CVE-2015-5286) References ~~~~~~~~~~ - https://bugs.launchpad.net/bugs/1498163 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5286 Notes ~~~~~ - This fix will be included in future 2014.2.4 (juno) and 2015.1.2 (kilo) releases. -- Tristan Cacqueray OpenStack Vulnerability Management Team
stable/juno ( 2014.2.4 ) commit: https://git.openstack.org/cgit/openstack/glance/commit/?id=868d9161c60f839cbf53393b804d7c0c41338e5b
Submitted in mr#73697.
Releasing Cloud 5 update. Not fixing openSUSE 13.1. Closing.
SUSE-SU-2016:0101-1: An update that solves two vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 945051,945994,947735 CVE References: CVE-2015-5251,CVE-2015-5286 Sources used: SUSE OpenStack Cloud 5 (src): openstack-glance-2014.2.4.juno-14.1, openstack-glance-doc-2014.2.4.juno-14.1