VDB
KO
MEDIUM 5.5

PYSEC-2017-143

Details

The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / glance
Introduced in: 0

No fixed version published yet for glance (pip). Pin to a known-safe version or switch to an alternative.

References