CVE-2012-4573
published 2012-11-11CVE-2012-4573: The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an…
PriorityP431medium5.5CVSS 2.0
AVNACLAuSCNIPAP
EPSS
3.32%
87.2th percentile
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glance | < glance 2012.1.1-3 (bookworm) | glance 2012.1.1-3 (bookworm) |
| debian | glance | < glance 2012.1.1-2 (bookworm) | glance 2012.1.1-2 (bookworm) |
| glance_project | glance | < b591304b8980d8aca8fa6cda9ea1621aca000c88 | b591304b8980d8aca8fa6cda9ea1621aca000c88 |
| glance_project | glance | >= 0 < 2012.1.1-3 | 2012.1.1-3 |
| glance_project | glance | >= 0 < 2012.1.1-2 | 2012.1.1-2 |
| glance_project | glance | >= 0 < 2012.1.1-3 | 2012.1.1-3 |
| glance_project | glance | >= 0 < 2012.1.1-2 | 2012.1.1-2 |
| glance_project | glance | >= 0 < 2012.1.1-3 | 2012.1.1-3 |
| glance_project | glance | >= 0 < 2012.1.1-2 | 2012.1.1-2 |
| glance_project | glance | >= 0 < 2012.1.1-3 | 2012.1.1-3 |
| glance_project | glance | >= 0 < 2012.1.1-2 | 2012.1.1-2 |
| glance_project | glance | >= 0 < 11.0.0a0 | 11.0.0a0 |
| glance_project | glance | >= 0 < fc0ee7623ec59c87ac6fc671e95a9798d6f2e2c3 | fc0ee7623ec59c87ac6fc671e95a9798d6f2e2c3 |
| openstack | essex | — | — |
| openstack | folsom | — | — |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
ghsa5.5MEDIUM
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Glance vulnerability
vendor_ubuntu·2012-11-09
CVE-2012-4573 Glance vulnerability
Title: Glance vulnerability
Summary: Glance could be made to delete arbitrary images.
USN-1626-1 fixed vulnerabilities in the v1 API of Glance. This update
provides the corresponding updates for the v2 API.
Original advisory details:
Gabe Westmaas discovered that Glance did not always properly enforce access
controls when deleting images. An authenticated user could delete arbitrary
images by using the v1 API under certain circumstances.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Glance vulnerability
vendor_ubuntu·2012-11-08
CVE-2012-4573 Glance vulnerability
Title: Glance vulnerability
Summary: Glance could be made to delete arbitrary images.
Gabe Westmaas discovered that Glance did not always properly enforce access
controls when deleting images. An authenticated user could delete arbitrary
images by using the v1 API under certain circumstances.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
OpenStack: Glance Authentication bypass for image deletion
vendor_redhat·2012-11-07·CVSS 5.5
CVE-2012-4573 [MEDIUM] OpenStack: Glance Authentication bypass for image deletion
OpenStack: Glance Authentication bypass for image deletion
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
Debian
CVE-2012-5482: glance - The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allo...
vendor_debian·2012·CVSS 5.5
CVE-2012-5482 [MEDIUM] CVE-2012-5482: glance - The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allo...
The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.
Scope: local
bookworm: resolved (fixed in 2012.1.1-3)
bullseye: resolved (fixed in 2012.1.1-3)
forky: resolved (fixed in 2012.1.1-3)
sid: resolved (fixed in 2012.1.1-3)
trixie: resolved (fixed in 2012.1.1-3)
Debian
CVE-2012-4573: glance - The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allo...
vendor_debian·2012·CVSS 5.5
CVE-2012-4573 [MEDIUM] CVE-2012-4573: glance - The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allo...
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
Scope: local
bookworm: resolved (fixed in 2012.1.1-2)
bullseye: resolved (fixed in 2012.1.1-2)
forky: resolved (fixed in 2012.1.1-2)
sid: resolved (fixed in 2012.1.1-2)
trixie: resolved (fixed in 2012.1.1-2)
OSV
OpenStack Glance arbitrary deletion of non-protected images
osv·2022-05-17·CVSS 5.5
CVE-2012-4573 [MEDIUM] OpenStack Glance arbitrary deletion of non-protected images
OpenStack Glance arbitrary deletion of non-protected images
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
GHSA
OpenStack Glance arbitrary deletion of non-protected images
ghsa·2022-05-17·CVSS 5.5
CVE-2012-5482 [MEDIUM] OpenStack Glance arbitrary deletion of non-protected images
OpenStack Glance arbitrary deletion of non-protected images
The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.
GHSA
OpenStack Glance arbitrary deletion of non-protected images
ghsa·2022-05-17·CVSS 5.5
CVE-2012-4573 [MEDIUM] OpenStack Glance arbitrary deletion of non-protected images
OpenStack Glance arbitrary deletion of non-protected images
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
OSV
OpenStack Glance arbitrary deletion of non-protected images
osv·2022-05-17·CVSS 5.5
CVE-2012-5482 [MEDIUM] OpenStack Glance arbitrary deletion of non-protected images
OpenStack Glance arbitrary deletion of non-protected images
The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.
OSV
CVE-2012-5482: The v2 API in OpenStack Glance Grizzly, Folsom (2012
osv·2012-11-11·CVSS 5.5
CVE-2012-5482 [MEDIUM] CVE-2012-5482: The v2 API in OpenStack Glance Grizzly, Folsom (2012
The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.
OSV
CVE-2012-4573: The v2 API in OpenStack Glance Grizzly, Folsom (2012
osv·2012-11-11·CVSS 5.5
CVE-2012-4573 [MEDIUM] CVE-2012-4573: The v2 API in OpenStack Glance Grizzly, Folsom (2012
The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.
OSV
CVE-2012-4573: The v1 API in OpenStack Glance Grizzly, Folsom (2012
osv·2012-11-11·CVSS 5.5
CVE-2012-4573 [MEDIUM] CVE-2012-4573: The v1 API in OpenStack Glance Grizzly, Folsom (2012
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4573, CVE-2012-5482 OpenStack: Glance Authentication bypass for image deletion [fedora-all]
bugzilla·2012-11-08·CVSS 5.5
CVE-2012-4573 [MEDIUM] CVE-2012-4573, CVE-2012-5482 OpenStack: Glance Authentication bypass for image deletion [fedora-all]
CVE-2012-4573, CVE-2012-5482 OpenStack: Glance Authentication bypass for image deletion [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Plea
Bugzilla
CVE-2012-4573, CVE-2012-5482 OpenStack: Glance Authentication bypass for image deletion [epel-6]
bugzilla·2012-11-08·CVSS 5.5
CVE-2012-4573 [MEDIUM] CVE-2012-4573, CVE-2012-5482 OpenStack: Glance Authentication bypass for image deletion [epel-6]
CVE-2012-4573, CVE-2012-5482 OpenStack: Glance Authentication bypass for image deletion [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epe
Bugzilla
CVE-2012-4573 OpenStack: Glance Authentication bypass for image deletion
bugzilla·2012-11-01·CVSS 5.5
CVE-2012-4573 [MEDIUM] CVE-2012-4573 OpenStack: Glance Authentication bypass for image deletion
CVE-2012-4573 OpenStack: Glance Authentication bypass for image deletion
Thierry Carrez ([email protected]) has released information reported by Gabe Westmaas (Rackspace):
Title: Authentication bypass for image deletion
Reporter: Gabe Westmaas (Rackspace)
Products: Glance
Affects: Essex, Folsom, Grizzly
Description:
Gabe Westmaas from Rackspace reported a vulnerability in Glance
authentication of image deletion requests. Authenticated users may be
able to delete arbitrary, non-protected images from Glance servers. Only
Folsom/Grizzly deployments that expose the v1 API are affected by this
vulnerability. Additionally, Essex deployments that use the
delayed_delete option are also affected.
Discussion:
Created attachment 636814
openstack-essex-glance-CVE-2012-4573.patch
---
Created
Bugzilla
CVE-2011-4573 JON: Incorrect delete permissions check
bugzilla·2011-12-05·CVSS 3.5
CVE-2011-4573 [LOW] CVE-2011-4573 JON: Incorrect delete permissions check
CVE-2011-4573 JON: Incorrect delete permissions check
JON did not verify that a user had the proper modify resource permissions when they attempted to delete a plug-in configuration update from the group connection properties history.
Discussion:
Patch commit:
http://git.fedorahosted.org/git/?p=rhq/rhq.git;a=commitdiff;h=24ba99780531d2f187528d7b555d79fab807467b
---
JON (RHQ) BZs:
https://bugzilla.redhat.com/show_bug.cgi?id=617649
https://bugzilla.redhat.com/show_bug.cgi?id=617653
---
This issue has been resolved in JON 3.0. A fix for this issue may be included in a future update for JON 2.4.1.
---
This issue has been addressed in following products:
JBoss Operations Network 2.4.2
Via RHSA-2012:0089 https://rhn.redhat.com/errata/RHSA-2012-0089.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092192.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00002.htmlhttp://osvdb.org/87248http://packetstormsecurity.com/files/118733/Red-Hat-Security-Advisory-2012-1558-01.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1558.htmlhttp://secunia.com/advisories/51174http://secunia.com/advisories/51234http://www.openwall.com/lists/oss-security/2012/11/07/6http://www.openwall.com/lists/oss-security/2012/11/09/5http://www.securityfocus.com/bid/56437http://www.ubuntu.com/usn/USN-1626-1http://www.ubuntu.com/usn/USN-1626-2https://bugs.launchpad.net/glance/+bug/1065187https://exchange.xforce.ibmcloud.com/vulnerabilities/79895https://github.com/openstack/glance/commit/6ab0992e5472ae3f9bef0d2ced41030655d9d2bchttps://github.com/openstack/glance/commit/90bcdc5a89e350a358cf320a03f5afe99795f6f6https://github.com/openstack/glance/commit/efd7e75b1f419a52c7103c7840e24af8e5deb29dhttp://lists.fedoraproject.org/pipermail/package-announce/2012-November/092192.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00002.htmlhttp://osvdb.org/87248http://packetstormsecurity.com/files/118733/Red-Hat-Security-Advisory-2012-1558-01.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1558.htmlhttp://secunia.com/advisories/51174http://secunia.com/advisories/51234http://www.openwall.com/lists/oss-security/2012/11/07/6http://www.openwall.com/lists/oss-security/2012/11/09/5http://www.securityfocus.com/bid/56437http://www.ubuntu.com/usn/USN-1626-1http://www.ubuntu.com/usn/USN-1626-2https://bugs.launchpad.net/glance/+bug/1065187https://exchange.xforce.ibmcloud.com/vulnerabilities/79895https://github.com/openstack/glance/commit/6ab0992e5472ae3f9bef0d2ced41030655d9d2bchttps://github.com/openstack/glance/commit/90bcdc5a89e350a358cf320a03f5afe99795f6f6https://github.com/openstack/glance/commit/efd7e75b1f419a52c7103c7840e24af8e5deb29d
2012-11-11
Published