GHSA-q748-mcwg-xmqv

Suggest an improvement
Source
https://github.com/advisories/GHSA-q748-mcwg-xmqv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-q748-mcwg-xmqv/GHSA-q748-mcwg-xmqv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q748-mcwg-xmqv
Aliases
Published
2022-05-17T04:04:02Z
Modified
2024-11-28T05:51:09.684559Z
Summary
OpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions
Details

OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*.

Database specific
{
    "nvd_published_at": "2015-10-26T17:59:00Z",
    "cwe_ids": [],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-02-08T17:59:13Z"
}
References

Affected packages

PyPI / glance

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2014.2.4

Affected versions

15.*

15.0.2

17.*

17.0.1

18.*

18.0.0.0b1
18.0.0.0rc1
18.0.0
18.0.1

19.*

19.0.0.0b1
19.0.0.0rc1
19.0.0.0rc2
19.0.0
19.0.1
19.0.2
19.0.3
19.0.4

20.*

20.0.0.0b1
20.0.0.0b2
20.0.0.0b3
20.0.0.0rc1
20.0.0.0rc2
20.0.0
20.0.1
20.1.0
20.2.0

21.*

21.0.0.0b1
21.0.0.0b2
21.0.0.0rc1
21.0.0.0rc2
21.0.0
21.1.0

22.*

22.0.0.0b2
22.0.0.0b3
22.0.0.0rc1
22.0.0
22.1.0
22.1.1

23.*

23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
23.0.0.0rc2
23.0.0
23.1.0

24.*

24.0.0.0rc1
24.0.0
24.1.0
24.2.0
24.2.1

25.*

25.0.0.0b2
25.0.0.0b3
25.0.0.0rc1
25.0.0
25.1.0

26.*

26.0.0.0b2
26.0.0.0b3
26.0.0.0rc1
26.0.0
26.1.0

27.*

27.0.0.0b1
27.0.0.0b2
27.0.0.0rc1
27.0.0
27.1.0

28.*

28.0.0.0b2
28.0.0.0rc1
28.0.0
28.0.1
28.1.0

29.*

29.0.0.0b1
29.0.0.0b2
29.0.0.0b3
29.0.0.0rc1
29.0.0

PyPI / glance

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2015.1.0
Fixed
2015.1.2