GHSA-r7pj-rvwg-vxhr

Suggest an improvement
Source
https://github.com/advisories/GHSA-r7pj-rvwg-vxhr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-r7pj-rvwg-vxhr/GHSA-r7pj-rvwg-vxhr.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-r7pj-rvwg-vxhr
Aliases
Published
2022-05-17T04:42:42Z
Modified
2023-11-08T03:57:32.366894Z
Summary
OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
Details

The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.

Database specific
{
    "nvd_published_at": "2014-04-27T20:55:00Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-20"
    ],
    "github_reviewed_at": "2023-02-08T19:59:42Z"
}
References

Affected packages

PyPI / glance

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2013.2
Fixed
2013.2.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-r7pj-rvwg-vxhr/GHSA-r7pj-rvwg-vxhr.json"