GHSA-q73f-vjc2-3gqf

Suggest an improvement
Source
https://github.com/advisories/GHSA-q73f-vjc2-3gqf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-q73f-vjc2-3gqf/GHSA-q73f-vjc2-3gqf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q73f-vjc2-3gqf
Aliases
Published
2022-05-17T03:44:51Z
Modified
2024-11-26T18:27:54Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenStack Image Service (Glance) allows remote authenticated users to read arbitrary file
Details

The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image.

Database specific
{
    "nvd_published_at": "2015-08-19T15:59:00Z",
    "cwe_ids": [
        "CWE-200"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2023-02-08T18:01:32Z"
}
References

Affected packages

PyPI / glance

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2015.1.0
Fixed
2015.1.2