Vulnerability in Glance. By submitting a HTTP PUT request with a 'x-image-meta-status' header, a tenant can manipulate the status of their images. A malicious tenant may exploit this flaw to reactivate disabled images, bypass storage quotas and in some cases replace image contents. Setups using the Glance v1 API allow the illegal modification of image status. Setups which also use the v2 API may allow a subsequent re-upload of image contents. Acknowledgements: Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Hemanth Makkapati of Rackspace as the original reporter.
Created attachment 1074617 [details] Upstream patch-Kilo
Created attachment 1074618 [details] Upstream patch-Juno
Created attachment 1074619 [details] Upstream patch-Liberty
Created openstack-glance tracking bugs for this issue: Affects: fedora-all [bug 1270680] Affects: openstack-rdo [bug 1270681]
This issue has been addressed in the following products: OpenStack 5 for RHEL 6 OpenStack 5 for RHEL 7 OpenStack 6 for RHEL 7 OpenStack 7 For RHEL 7 Via RHSA-2015:1897 https://rhn.redhat.com/errata/RHSA-2015-1897.html