2.8

CVE-2022-4134

A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Openstack Version 13
Redhat ≫ Openstack Version 16.1
Redhat ≫ Openstack Version 16.2 Update -
Redhat ≫ Openstack Version 17
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.239
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.8 1.3 1.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CISA-ADP 2.8 1.3 1.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CWE-829 Inclusion of Functionality from Untrusted Control Sphere

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

https://bugs.launchpad.net/glance/+bug/1990157
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2147462
Issue Tracking
https://wiki.openstack.org/wiki/OSSN/OSSN-0090
Vendor Advisory