CVE-2012-5482
published 2012-11-11CVE-2012-5482: The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an…
PriorityP428medium5.5CVSS 2.0
AVNACLAuSCNIPAP
EPSS
2.72%
84.3th percentile
The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glance | < glance 2012.1.1-3 (bookworm) | glance 2012.1.1-3 (bookworm) |
| debian | glance | < glance 2012.1.1-2 (bookworm) | glance 2012.1.1-2 (bookworm) |
| glance_project | glance | < efd7e75b1f419a52c7103c7840e24af8e5deb29d | efd7e75b1f419a52c7103c7840e24af8e5deb29d |
| glance_project | glance | < 6ab0992e5472ae3f9bef0d2ced41030655d9d2bc | 6ab0992e5472ae3f9bef0d2ced41030655d9d2bc |
| glance_project | glance | >= 0 < 2012.1.1-3 | 2012.1.1-3 |
| glance_project | glance | >= 0 < 2012.1.1-2 | 2012.1.1-2 |
| glance_project | glance | >= 0 < 2012.1.1-3 | 2012.1.1-3 |
| glance_project | glance | >= 0 < 2012.1.1-2 | 2012.1.1-2 |
| glance_project | glance | >= 0 < 2012.1.1-3 | 2012.1.1-3 |
| glance_project | glance | >= 0 < 2012.1.1-2 | 2012.1.1-2 |
| glance_project | glance | >= 0 < 2012.1.1-3 | 2012.1.1-3 |
| glance_project | glance | >= 0 < 2012.1.1-2 | 2012.1.1-2 |
| glance_project | glance | >= 0 < 11.0.0a0 | 11.0.0a0 |
| glance_project | glance | >= 0 < 90bcdc5a89e350a358cf320a03f5afe99795f6f6 | 90bcdc5a89e350a358cf320a03f5afe99795f6f6 |
| openstack | essex | — | — |
| openstack | folsom | — | — |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
ghsa5.5MEDIUM
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
OpenStack: Glance Authentication bypass for image deletion
vendor_redhat·2012-11-07·CVSS 5.5
CVE-2012-4573 [MEDIUM] OpenStack: Glance Authentication bypass for image deletion
OpenStack: Glance Authentication bypass for image deletion
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
Debian
CVE-2012-5482: glance - The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allo...
vendor_debian·2012·CVSS 5.5
CVE-2012-5482 [MEDIUM] CVE-2012-5482: glance - The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allo...
The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.
Scope: local
bookworm: resolved (fixed in 2012.1.1-3)
bullseye: resolved (fixed in 2012.1.1-3)
forky: resolved (fixed in 2012.1.1-3)
sid: resolved (fixed in 2012.1.1-3)
trixie: resolved (fixed in 2012.1.1-3)
Debian
CVE-2012-4573: glance - The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allo...
vendor_debian·2012·CVSS 5.5
CVE-2012-4573 [MEDIUM] CVE-2012-4573: glance - The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allo...
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
Scope: local
bookworm: resolved (fixed in 2012.1.1-2)
bullseye: resolved (fixed in 2012.1.1-2)
forky: resolved (fixed in 2012.1.1-2)
sid: resolved (fixed in 2012.1.1-2)
trixie: resolved (fixed in 2012.1.1-2)
OSV
OpenStack Glance arbitrary deletion of non-protected images
osv·2022-05-17·CVSS 5.5
CVE-2012-4573 [MEDIUM] OpenStack Glance arbitrary deletion of non-protected images
OpenStack Glance arbitrary deletion of non-protected images
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
GHSA
OpenStack Glance arbitrary deletion of non-protected images
ghsa·2022-05-17·CVSS 5.5
CVE-2012-5482 [MEDIUM] OpenStack Glance arbitrary deletion of non-protected images
OpenStack Glance arbitrary deletion of non-protected images
The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.
GHSA
OpenStack Glance arbitrary deletion of non-protected images
ghsa·2022-05-17·CVSS 5.5
CVE-2012-4573 [MEDIUM] OpenStack Glance arbitrary deletion of non-protected images
OpenStack Glance arbitrary deletion of non-protected images
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
OSV
OpenStack Glance arbitrary deletion of non-protected images
osv·2022-05-17·CVSS 5.5
CVE-2012-5482 [MEDIUM] OpenStack Glance arbitrary deletion of non-protected images
OpenStack Glance arbitrary deletion of non-protected images
The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.
OSV
CVE-2012-5482: The v2 API in OpenStack Glance Grizzly, Folsom (2012
osv·2012-11-11·CVSS 5.5
CVE-2012-5482 [MEDIUM] CVE-2012-5482: The v2 API in OpenStack Glance Grizzly, Folsom (2012
The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.
OSV
CVE-2012-5482: The v1 API in OpenStack Glance Grizzly, Folsom (2012
osv·2012-11-11·CVSS 5.5
CVE-2012-5482 [MEDIUM] CVE-2012-5482: The v1 API in OpenStack Glance Grizzly, Folsom (2012
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
OSV
CVE-2012-4573: The v1 API in OpenStack Glance Grizzly, Folsom (2012
osv·2012-11-11·CVSS 5.5
CVE-2012-4573 [MEDIUM] CVE-2012-4573: The v1 API in OpenStack Glance Grizzly, Folsom (2012
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4573, CVE-2012-5482 OpenStack: Glance Authentication bypass for image deletion [fedora-all]
bugzilla·2012-11-08·CVSS 5.5
CVE-2012-4573 [MEDIUM] CVE-2012-4573, CVE-2012-5482 OpenStack: Glance Authentication bypass for image deletion [fedora-all]
CVE-2012-4573, CVE-2012-5482 OpenStack: Glance Authentication bypass for image deletion [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Plea
Bugzilla
CVE-2012-4573, CVE-2012-5482 OpenStack: Glance Authentication bypass for image deletion [epel-6]
bugzilla·2012-11-08·CVSS 5.5
CVE-2012-4573 [MEDIUM] CVE-2012-4573, CVE-2012-5482 OpenStack: Glance Authentication bypass for image deletion [epel-6]
CVE-2012-4573, CVE-2012-5482 OpenStack: Glance Authentication bypass for image deletion [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epe
Bugzilla
CVE-2012-4573 OpenStack: Glance Authentication bypass for image deletion
bugzilla·2012-11-01·CVSS 5.5
CVE-2012-4573 [MEDIUM] CVE-2012-4573 OpenStack: Glance Authentication bypass for image deletion
CVE-2012-4573 OpenStack: Glance Authentication bypass for image deletion
Thierry Carrez ([email protected]) has released information reported by Gabe Westmaas (Rackspace):
Title: Authentication bypass for image deletion
Reporter: Gabe Westmaas (Rackspace)
Products: Glance
Affects: Essex, Folsom, Grizzly
Description:
Gabe Westmaas from Rackspace reported a vulnerability in Glance
authentication of image deletion requests. Authenticated users may be
able to delete arbitrary, non-protected images from Glance servers. Only
Folsom/Grizzly deployments that expose the v1 API are affected by this
vulnerability. Additionally, Essex deployments that use the
delayed_delete option are also affected.
Discussion:
Created attachment 636814
openstack-essex-glance-CVE-2012-4573.patch
---
Created
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092192.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00002.htmlhttp://osvdb.org/87248http://secunia.com/advisories/51174http://www.openwall.com/lists/oss-security/2012/11/07/6http://www.openwall.com/lists/oss-security/2012/11/08/2http://www.openwall.com/lists/oss-security/2012/11/09/1http://www.openwall.com/lists/oss-security/2012/11/09/5http://www.securityfocus.com/bid/56437https://bugs.launchpad.net/glance/+bug/1076506https://exchange.xforce.ibmcloud.com/vulnerabilities/80019https://github.com/openstack/glance/commit/b591304b8980d8aca8fa6cda9ea1621aca000c88https://github.com/openstack/glance/commit/fc0ee7623ec59c87ac6fc671e95a9798d6f2e2c3http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092192.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-11/msg00002.htmlhttp://osvdb.org/87248http://secunia.com/advisories/51174http://www.openwall.com/lists/oss-security/2012/11/07/6http://www.openwall.com/lists/oss-security/2012/11/08/2http://www.openwall.com/lists/oss-security/2012/11/09/1http://www.openwall.com/lists/oss-security/2012/11/09/5http://www.securityfocus.com/bid/56437https://bugs.launchpad.net/glance/+bug/1076506https://exchange.xforce.ibmcloud.com/vulnerabilities/80019https://github.com/openstack/glance/commit/b591304b8980d8aca8fa6cda9ea1621aca000c88https://github.com/openstack/glance/commit/fc0ee7623ec59c87ac6fc671e95a9798d6f2e2c3
2012-11-11
Published