CVE-2024-32498
- EPSS 0.07%
- Veröffentlicht 05.07.2024 02:15:09
- Zuletzt bearbeitet 21.11.2024 09:15:02
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an...
CVE-2022-4134
- EPSS 0.09%
- Veröffentlicht 06.03.2023 23:15:11
- Zuletzt bearbeitet 06.03.2025 20:15:37
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
CVE-2022-47951
- EPSS 0.57%
- Veröffentlicht 26.01.2023 22:15:25
- Zuletzt bearbeitet 31.03.2025 17:15:39
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image ...
CVE-2016-8611
- EPSS 0.54%
- Veröffentlicht 31.07.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 02:59:40
A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2 `/images` API POST method for authenticated users, resulting in possible denial of service attacks through database table saturat...
CVE-2015-8234
- EPSS 0.25%
- Veröffentlicht 29.03.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.
CVE-2017-7200
- EPSS 0.38%
- Veröffentlicht 21.03.2017 06:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'http://localhos...
CVE-2015-5162
- EPSS 3.2%
- Veröffentlicht 07.10.2016 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk c...
CVE-2015-5163
- EPSS 0.24%
- Veröffentlicht 19.08.2015 15:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image.
- EPSS 0.36%
- Veröffentlicht 14.08.2015 18:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
OpenStack Glance before 2015.1.1 (kilo) allows remote authenticated users to cause a denial of service (disk consumption) by repeatedly using the import task flow API to create images and then deleting them.
CVE-2013-4428
- EPSS 0.28%
- Veröffentlicht 27.10.2013 00:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated user...