VDB
KO
MEDIUM

GHSA-pwrj-f53c-f89j

OpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme

Details

The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users to read or delete arbitrary files via a full pathname in a `filesystem://` URL in the image location property. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9493.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / glance
Introduced in: 0 Fixed in: 11.0.0a0
Fix pip install --upgrade 'glance>=11.0.0a0'

References