VDB
Sign up

PYSEC-2012-29

Withdrawn 2024-11-22. This finding no longer applies and is kept for reference. It is not used when checking packages.

Quick fix

PYSEC-2012-29 — glance: upgrade to the fixed version with the command below.

pip install --upgrade 'glance>=90bcdc5a89e350a358cf320a03f5afe99795f6f6'

Details

The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/glance
Introduced in: 0Fixed in: 90bcdc5a89e350a358cf320a03f5afe99795f6f6
Fixpip install --upgrade 'glance>=90bcdc5a89e350a358cf320a03f5afe99795f6f6'

References