CVE-2015-5251: Medium severity openstack glance vulnerability
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5251?
CVE-2015-5251 is considered a moderate severity vulnerability due to its impact on image status management in OpenStack Glance.
How do I fix CVE-2015-5251?
To fix CVE-2015-5251, upgrade OpenStack Glance to version 2014.2.4 or 2015.1.2 or later.
What systems are affected by CVE-2015-5251?
CVE-2015-5251 affects OpenStack Glance versions prior to 2014.2.4 and 2015.1.x versions before 2015.1.2.
What type of attack can exploit CVE-2015-5251?
CVE-2015-5251 can be exploited by remote authenticated users to change the status of their images and bypass access restrictions.
Is there any workaround for CVE-2015-5251?
There are no known effective workarounds for CVE-2015-5251, so upgrading is recommended.