GHSA-q748-mcwg-xmqv

Suggest an improvement
Source
https://github.com/advisories/GHSA-q748-mcwg-xmqv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-q748-mcwg-xmqv/GHSA-q748-mcwg-xmqv.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-q748-mcwg-xmqv
Aliases
Published
2022-05-17T04:04:02Z
Modified
2026-07-07T11:56:34Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions
Details

OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*.

Database specific
{
    "cwe_ids":  [
        "CWE-863"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-02-08T17:59:13Z",
    "nvd_published_at":  "2015-10-26T17:59:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

PyPI / glance

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2011.2
Fixed
2014.2.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-q748-mcwg-xmqv/GHSA-q748-mcwg-xmqv.json"

PyPI / glance

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2015.1.0
Fixed
2015.1.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-q748-mcwg-xmqv/GHSA-q748-mcwg-xmqv.json"