2.2
CVE-2026-77648
- EPSS -
- Veröffentlicht 20.08.2026 22:37:31
- Zuletzt bearbeitet 20.08.2026 23:16:28
- CVE-Watchlists
- Unerledigt
In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerOpenStack
≫
Produkt
Glance
Default Statusunaffected
Version
30.0.0
Version <
30.3.0
Status
affected
Version
31.0.0
Version <
31.1.1
Status
affected
Version
32.0.0
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 2.2 | 0.7 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://wiki.openstack.org/wiki/OSSN/OSSN-0105
https://www.openwall.com/lists/oss-security/2026/08/11/7