CVE-2016-0757: Medium severity openstack glance vulnerability
OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when showmultiplelocations is enabled, allow remote authenticated users to change image status and upload new image data by removing the last location of an image.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0757?
CVE-2016-0757 is classified as a moderate severity vulnerability.
How do I fix CVE-2016-0757?
To fix CVE-2016-0757, upgrade OpenStack Glance to version 11.0.2 or later if using Liberty, or 2015.1.3 or later if using Kilo.
Who is affected by CVE-2016-0757?
CVE-2016-0757 affects remote authenticated users of OpenStack Glance versions prior to 11.0.2 and 2015.1.3.
What actions can be taken by an attacker exploiting CVE-2016-0757?
An attacker exploiting CVE-2016-0757 can change the image status and upload new image data by removing the last location of an image.
Is there a workaround for CVE-2016-0757?
A temporary workaround for CVE-2016-0757 is to disable the show_multiple_locations feature in OpenStack Glance.