CVE-2014-9493
published 2015-01-07CVE-2014-9493: The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary…
PriorityP428medium5.5CVSS 2.0
AVNACLAuSCPINAP
EPSS
2.77%
84.8th percentile
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glance | < glance 2014.1.3-11 (bookworm) | glance 2014.1.3-11 (bookworm) |
| debian | glance | < glance 2014.1.3-6 (bookworm) | glance 2014.1.3-6 (bookworm) |
| glance_project | glance | >= 0 < 2014.1.3-11 | 2014.1.3-11 |
| glance_project | glance | >= 0 < 2014.1.3-6 | 2014.1.3-6 |
| glance_project | glance | >= 0 < 2014.1.3-11 | 2014.1.3-11 |
| glance_project | glance | >= 0 < 2014.1.3-6 | 2014.1.3-6 |
| glance_project | glance | >= 0 < 2014.1.3-11 | 2014.1.3-11 |
| glance_project | glance | >= 0 < 2014.1.3-6 | 2014.1.3-6 |
| glance_project | glance | >= 0 < 2014.1.3-11 | 2014.1.3-11 |
| glance_project | glance | >= 0 < 2014.1.3-6 | 2014.1.3-6 |
| glance_project | glance | >= 0 < 11.0.0a0 | 11.0.0a0 |
| openstack | image_registry_and_delivery_service | >= 2014.1 < 2014.1.4 | 2014.1.4 |
| openstack | image_registry_and_delivery_service | >= 2014.2 < 2014.2.2 | 2014.2.2 |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
ghsa5.5MEDIUM
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-glance: unrestricted path traversal flaw (incomplete fix for CVE-2014-9493) (OSSA 2015-002)
vendor_redhat·2015-01-12·CVSS 5.5
CVE-2015-1195 [MEDIUM] CWE-22 openstack-glance: unrestricted path traversal flaw (incomplete fix for CVE-2014-9493) (OSSA 2015-002)
openstack-glance: unrestricted path traversal flaw (incomplete fix for CVE-2014-9493) (OSSA 2015-002)
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users to read or delete arbitrary files via a full pathname in a filesystem: URL in the image location property. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9493.
It was discovered that the fix for CVE-2014-9493 was incomplete: an authenticated user could use a path traversal flaw in glance to download or delete any file on the glance server that is accessible to the glance process user. Note that only setups using the OpenStack Image V2 API were affected by this flaw.
Statement: The fix for CVE-2014-9493 is complete
Debian
CVE-2015-1195: glance - The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014...
vendor_debian·2015·CVSS 5.5
CVE-2015-1195 [MEDIUM] CVE-2015-1195: glance - The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014...
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users to read or delete arbitrary files via a full pathname in a filesystem: URL in the image location property. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9493.
Scope: local
bookworm: resolved (fixed in 2014.1.3-11)
bullseye: resolved (fixed in 2014.1.3-11)
forky: resolved (fixed in 2014.1.3-11)
sid: resolved (fixed in 2014.1.3-11)
trixie: resolved (fixed in 2014.1.3-11)
Red Hat
openstack-glance: unrestricted path traversal flaw
vendor_redhat·2014-12-15·CVSS 5.5
CVE-2014-9493 [MEDIUM] CWE-22 openstack-glance: unrestricted path traversal flaw
openstack-glance: unrestricted path traversal flaw
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.
It was discovered that an authenticated user could use a path traversal flaw in glance to download or delete any file on the glance server that is accessible to the glance process user. Note that only setups using the OpenStack Image V2 API were affected by this flaw.
Mitigation: diff --git a/etc/policy.json b/etc/policy.json
index 325f00b..a797f12 100644
--- a/etc/policy.json
+++ b/etc/policy.json
@@ -13,9 +13,9 @@
"download_image": "",
"upload_image": "",
- "delete_image_location": "",
- "get_image_locatio
Debian
CVE-2014-9493: glance - The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014...
vendor_debian·2014·CVSS 5.5
CVE-2014-9493 [MEDIUM] CVE-2014-9493: glance - The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014...
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.
Scope: local
bookworm: resolved (fixed in 2014.1.3-6)
bullseye: resolved (fixed in 2014.1.3-6)
forky: resolved (fixed in 2014.1.3-6)
sid: resolved (fixed in 2014.1.3-6)
trixie: resolved (fixed in 2014.1.3-6)
GHSA
GHSA-jgr4-76hh-5p7q: The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014
ghsa_unreviewed·2022-05-14
CVE-2014-9493 [MEDIUM] GHSA-jgr4-76hh-5p7q: The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.
GHSA
OpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme
ghsa·2022-05-14·CVSS 5.5
CVE-2015-1195 [MEDIUM] CWE-22 OpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme
OpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users to read or delete arbitrary files via a full pathname in a `filesystem://` URL in the image location property. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9493.
OSV
OpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme
osv·2022-05-14·CVSS 5.5
CVE-2015-1195 [MEDIUM] OpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme
OpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users to read or delete arbitrary files via a full pathname in a `filesystem://` URL in the image location property. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9493.
OSV
CVE-2015-1195: The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014
osv·2015-01-21·CVSS 5.5
CVE-2015-1195 [MEDIUM] CVE-2015-1195: The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users to read or delete arbitrary files via a full pathname in a filesystem: URL in the image location property. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9493.
OSV
CVE-2014-9493: The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014
osv·2015-01-07·CVSS 5.5
CVE-2014-9493 [MEDIUM] CVE-2014-9493: The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1195 openstack-glance: unrestricted path traversal flaw (incomplete fix for CVE-2014-9493) (OSSA 2015-002)
bugzilla·2015-01-13·CVSS 5.5
CVE-2015-1195 [MEDIUM] CVE-2015-1195 openstack-glance: unrestricted path traversal flaw (incomplete fix for CVE-2014-9493) (OSSA 2015-002)
CVE-2015-1195 openstack-glance: unrestricted path traversal flaw (incomplete fix for CVE-2014-9493) (OSSA 2015-002)
Title: Glance v2 API unrestricted path traversal through filesystem:// scheme
Reporter: Jin Liu (EMC)
Products: Glance
Versions: up to 2014.1.3 and 2014.2 versions up to 2014.2.1
Description:
Jin Liu from EMC reported that path traversal vulnerabilities in Glance were not fully patched in OSSA 2014-041. By setting a malicious image location to a filesystem:// scheme an authenticated user can still download or delete any file on the Glance server for which the Glance process user has access to. Only setups using the Glance V2 API are affected by this flaw.
References:
https://launchpad.net/bugs/1408663
Acknowledgements:
Red Hat would like to thank the OpenStack project fo
Bugzilla
CVE-2014-9493 openstack-glance: unrestricted path traversal flaw
bugzilla·2014-12-15·CVSS 5.5
CVE-2014-9493 [MEDIUM] CVE-2014-9493 openstack-glance: unrestricted path traversal flaw
CVE-2014-9493 openstack-glance: unrestricted path traversal flaw
Title: Glance v2 API unrestricted path traversal
Reporter: Masahito Muroi (NTT)
Products: Glance
Versions: up to 2014.1.3 and 2014.2 version up to 2014.2.1
Description:
Masahito Muroi from NTT reported a vulnerability in Glance. By setting a malicious image location an authenticated user can download or delete any file on the Glance server for which the Glance process user has access to. Only setups using the Glance V2 API are affected by this flaw.
Note:
A potential mitigation strategy available for operators is to change the glance policy to restrict access to administrators for get_image_location, set_image_location, and delete_image_location. An example patch to be applied to /etc/glance/policy.json is attached.
Refer
http://lists.openstack.org/pipermail/openstack-announce/2014-December/000317.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0246.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.securityfocus.com/bid/71688https://bugs.launchpad.net/glance/+bug/1400966https://security.openstack.org/ossa/OSSA-2014-041.htmlhttp://lists.openstack.org/pipermail/openstack-announce/2014-December/000317.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0246.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.securityfocus.com/bid/71688https://bugs.launchpad.net/glance/+bug/1400966https://security.openstack.org/ossa/OSSA-2014-041.html
2015-01-07
Published