Path Traversal Vulnerability in OpenStack Image Registry by OpenStack
CVE-2015-1195
Currently unrated
Key Information:
- Vendor
Openstack
- Vendor
- CVE Published:
- 21 January 2015
What is CVE-2015-1195?
The V2 API in OpenStack Image Registry and Delivery Service (Glance) is susceptible to a path traversal vulnerability that permits remote authenticated users to access or delete files on the server. This is achieved by manipulating the image location property with a full pathname in a filesystem URL. The issue arises from an incomplete resolution of a prior security concern, allowing the exploitation of critical file system operations. Users must ensure they are using patched versions to mitigate the risks associated with this vulnerability.