CVE-2015-5163: Infoleak
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image.
Other sources
Title: Glance v2 API host file disclosure through qcow2 backing file Reporter: Eric Harney (Red Hat) Products: Glance Affects: 2015.1.0 versions through 2015.1.1
Description: Eric Harney from Red Hat reported a vulnerability in Glance. By importing a qcow2 image with a malicious backing file, an authenticated user may mislead Glance import task action, resulting in the disclosure of any file on the Glance server for which the Glance process user has access to. Only setups using the Glance V2 API are affected by this flaw.
Proposed patch: See attached patches. Unless a flaw is discovered in them, these patches will be merged to stable/kilo and master on the public disclosure date.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5163?
CVE-2015-5163 has been classified with a moderate severity level, indicating a potential risk to system confidentiality.
How do I fix CVE-2015-5163?
To fix CVE-2015-5163, upgrade OpenStack Glance to version 2015.1.2 or later.
What does CVE-2015-5163 affect?
CVE-2015-5163 affects OpenStack Glance versions 2015.1.0 and 2015.1.1 when using the V2 API.
What type of vulnerability is CVE-2015-5163?
CVE-2015-5163 is a file disclosure vulnerability allowing remote authenticated users to read arbitrary files.
When was CVE-2015-5163 reported?
CVE-2015-5163 was reported in August 2015, affecting OpenStack Kilo releases.