ossa/ossa/OSSA-2014-012.yaml
Thierry Carrez 62af610079 Import basic repository structure
Prepare for repository publication by:
- moving all YAML under ossa/
- cargo-culting doc building from openstack/governance
- adding a LICENSE (CC 3.0 BY)

Change-Id: I68354a7b75060ed5012e16048e40ffb61007ff9d
2014-12-01 11:27:31 +01:00

62 lines
1.4 KiB
YAML

date: 2014-04-10
id: OSSA-2014-012
title: 'Remote code execution in Glance Sheepdog backend'
description: 'Paul McMillan from Nebula reported a vulnerability in Glance Sheepdog
backend. By using a specially crafted location, a user allowed to insert or modify
Glance image metadata may trigger code execution on the Glance host as the user
the Glance service runs under. This may result in Glance host unauthorized access
and further compromise of the Glance service. All setups using Glance server with
the (enabled by default) sheepdog backend are affected.'
reference: http://lists.openstack.org/pipermail/openstack-announce/2014-April/000220.html
affected-products:
- product: glance
version: from 2013.2 to 2013.2.3
vulnerabilities:
- cve-id: CVE-2014-0162
impact-assessment:
source: 'Red Hat Product Security'
rating: important
assessment:
type: CVSS2
score: 6.5
detail: AV:N/AC:L/Au:S/C:P/I:P/A:P
classification:
source: 'Red Hat Product Security'
type: CWE
detail: TODO
reporters:
- name: 'Paul McMillan'
affiliation: Nebula
reported:
- CVE-2014-0162
issues:
links:
- https://launchpad.net/bugs/1298698
type: launchpad
reviews:
juno:
- https://review.openstack.org/#/c/86622
icehouse:
- https://review.openstack.org/#/c/86625
havana:
- https://review.openstack.org/#/c/86626
type: gerrit