Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-4134

Опубликовано: 14 окт. 2022
Источник: redhat
CVSS3: 4.8

Описание

A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.

Отчет

You must be using Ceph as a backend to be affected by this flaw. As this flaw would involve significant architectural changes, the impact is moderate. A fix will not be produced for Red Hat OpenStack Platform 16.2 and older releases. If you are concerned about the risk of this flaw against your environment, please follow guidance in the mitigation section, but understand this comes with performance tradeoffs.

Меры по смягчению последствий

There are two options:

  1. Manually disable the show_multiple_locations configuration setting (change it to false).
  2. Keep show_multiple_locations enabled, but restrict the glance-api service from being exposed directly to end users. Refer the upstream OSSN listed in the external references section for further details.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)openstack-glanceWill not fix
Red Hat OpenStack Platform 16.1openstack-glanceWill not fix
Red Hat OpenStack Platform 16.2openstack-glanceFix deferred
Red Hat OpenStack Platform 17.0openstack-glanceFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-829
https://bugzilla.redhat.com/show_bug.cgi?id=2147462openstack: glance & ceph conflict which allows image tampering

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 2.8
ubuntu
почти 3 года назад

A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.

CVSS3: 2.8
nvd
почти 3 года назад

A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.

CVSS3: 2.8
debian
почти 3 года назад

A flaw was found in openstack-glance. This issue could allow a remote, ...

CVSS3: 2.8
github
почти 3 года назад

OpenStack Glance Inclusion of Functionality from Untrusted Control Sphere vulnerability

4.8 Medium

CVSS3