Comment 17 for bug 1400966

Revision history for this message
Thierry Carrez (ttx) wrote : Re: Glance allows users to download and delete any file in glance-api server

Since this was unfortunately disclosed too early, posting a mitigation solution would be good. My understaning is that setting the set_image_location policy to admin-only is a way to work around the issue temporarily. Glance core, could you confirm ?