It was discovered that an authenticated user could use a path traversal flaw in glance to download or delete any file on the glance server that is accessible to the glance process user. Note that only setups using the OpenStack Image V2 API were affected by this flaw.
Find out more about CVE-2014-9493 from the MITRE CVE dictionary dictionary and NIST NVD.
Base Score | 5.5 |
---|---|
Base Metrics | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Access Vector | Network |
Access Complexity | Low |
Authentication | Single |
Confidentiality Impact | Partial |
Integrity Impact | Partial |
Availability Impact | None |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 (openstack-glance) | RHSA-2015:0246 | 2015-02-19 |
Red Hat Enterprise Linux OpenStack Platform 4.0 (openstack-glance) | RHSA-2015:0246 | 2015-02-19 |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 (openstack-glance) | RHSA-2015:0246 | 2015-02-19 |
Platform | Package | State |
---|---|---|
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | openstack-glance | Affected |