CVE-2015-8234: Medium severity openstack glance store vulnerability
Published Mar 29, 2017
·Updated
The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.
Affected Software
2 affected components
pip/glance<=11.0.0
Openstack Glance=11.0.0
Remediation
Patch Available
Event History
Mar 29, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 17, 2022
Advisory Published
02:52 AM
Frequently Asked Questions
1
What is the severity of CVE-2015-8234?
CVE-2015-8234 is considered a high severity vulnerability due to its potential for remote exploitation.
2
How do I fix CVE-2015-8234?
To fix CVE-2015-8234, upgrade OpenStack Glance to a version that is not vulnerable to this issue.
3
Who is affected by CVE-2015-8234?
CVE-2015-8234 affects users running OpenStack Glance version 11.0.0.
4
What type of attack does CVE-2015-8234 enable?
CVE-2015-8234 enables attackers to bypass the image signature verification process using a crafted image.
5
What is the impact of CVE-2015-8234?
The impact of CVE-2015-8234 can lead to unauthorized access or manipulation of images within OpenStack deployments.