CVE-2015-5163
published 2015-08-19CVE-2015-5163: The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read…
PriorityP422low3.5CVSS 2.0
AVNACMAuSCPINAN
EPSS
1.50%
71.2th percentile
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glance | < glance 2015.1.0-4 (bookworm) | glance 2015.1.0-4 (bookworm) |
| glance_project | glance | >= 0 < 2015.1.0-4 | 2015.1.0-4 |
| glance_project | glance | >= 0 < 2015.1.0-4 | 2015.1.0-4 |
| glance_project | glance | >= 0 < 2015.1.0-4 | 2015.1.0-4 |
| glance_project | glance | >= 0 < 2015.1.0-4 | 2015.1.0-4 |
| glance_project | glance | >= 2015.1.0 < 2015.1.2 | 2015.1.2 |
| openstack | glance | — | — |
| openstack | glance | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
osv3.5LOW
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Image Service (Glance) allows remote authenticated users to read arbitrary file
osv·2022-05-17
CVE-2015-5163 [HIGH] OpenStack Image Service (Glance) allows remote authenticated users to read arbitrary file
OpenStack Image Service (Glance) allows remote authenticated users to read arbitrary file
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image.
GHSA
OpenStack Image Service (Glance) allows remote authenticated users to read arbitrary file
ghsa·2022-05-17
CVE-2015-5163 [HIGH] CWE-200 OpenStack Image Service (Glance) allows remote authenticated users to read arbitrary file
OpenStack Image Service (Glance) allows remote authenticated users to read arbitrary file
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image.
OSV
CVE-2015-5163: The import task action in OpenStack Image Service (Glance) 2015
osv·2015-08-19·CVSS 3.5
CVE-2015-5163 [LOW] CVE-2015-5163: The import task action in OpenStack Image Service (Glance) 2015
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image.
Red Hat
openstack-glance: Glance v2 API host file disclosure through qcow2 backing file
vendor_redhat·2015-08-13·CVSS 3.5
CVE-2015-5163 [LOW] CWE-454 openstack-glance: Glance v2 API host file disclosure through qcow2 backing file
openstack-glance: Glance v2 API host file disclosure through qcow2 backing file
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image.
A flaw was found in the OpenStack Image Service (glance) import task action. When processing a malicious qcow2 header, glance could be tricked into reading an arbitrary file from the glance host. Only setups using the glance V2 API are affected by this flaw.
Package: openstack-glance (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: openstack-glance (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Not affected
Debian
CVE-2015-5163: glance - The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015....
vendor_debian·2015·CVSS 3.5
CVE-2015-5163 [LOW] CVE-2015-5163: glance - The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015....
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image.
Scope: local
bookworm: resolved (fixed in 2015.1.0-4)
bullseye: resolved (fixed in 2015.1.0-4)
forky: resolved (fixed in 2015.1.0-4)
sid: resolved (fixed in 2015.1.0-4)
trixie: resolved (fixed in 2015.1.0-4)
No detection rules found.
No public exploits indexed.
http://lists.openstack.org/pipermail/openstack-announce/2015-August/000527.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1639.htmlhttp://www.securityfocus.com/bid/76346https://bugs.launchpad.net/glance/+bug/1471912http://lists.openstack.org/pipermail/openstack-announce/2015-August/000527.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1639.htmlhttp://www.securityfocus.com/bid/76346https://bugs.launchpad.net/glance/+bug/1471912
2015-08-19
Published