CVE-2015-5163 Information
Feb 14, 2021
cve
Description
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo) when using the V2 API allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image.
Reference
http://lists.openstack.org/pipermail/openstack-announce/2015-August/000527.html http://rhn.redhat.com/errata/RHSA-2015-1639.html http://www.securityfocus.com/bid/76346 https://bugs.launchpad.net/glance/+bug/1471912
Share on: