8.5

CVE-2016-4383

The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated users to cause other users to boot into a modified image without notification of the change.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp ≫ Helion Openstack Glance Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.74% 0.842
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.4 1.7 6
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
NIST 8.5 6.8 10
AV:N/AC:M/Au:S/C:C/I:C/A:C
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

http://www.securityfocus.com/bid/93106
Third Party Advisory
VDB Entry
https://bugs.launchpad.net/glance/+bug/1593799/
Third Party Advisory
VDB Entry
Issue Tracking
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05273584
Vendor Advisory
Mitigation
https://wiki.openstack.org/wiki/OSSN/OSSN-0075
Third Party Advisory
Technical Description