VDB
KO
MEDIUM

GHSA-vwr9-9f8v-vp5m

OpenStack Glance arbitrary deletion of non-protected images

Details

The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / glance
Introduced in: 0 Fixed in: 11.0.0a0
Fix pip install --upgrade 'glance>=11.0.0a0'

References