CVE-2015-5251
Last modified
CVE-2015-5251 is a vulnerability of currently unknown severity. OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*.. EPSS estimates a 2.04% chance of exploitation in the next 30 days.
Description
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openstack | Image Registry And Delivery Service \(Glance\) | <= 2014.2.3 |
| Openstack | Image Registry And Delivery Service \(Glance\) | 2015.1.0 |
| Openstack | Image Registry And Delivery Service \(Glance\) | 2015.1.1 |
References
- https://security.openstack.org/ossa/OSSA-2015-019.htmlVendor Advisory
- https://security.openstack.org/ossa/OSSA-2015-019.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-5251?
How severe is CVE-2015-5251?
How do I fix CVE-2015-5251?
Are you affected by CVE-2015-5251?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
