The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated users to cause other users to boot into a modified image without notification of the change.
{
"binaries": [
{
"binary_version": "2:12.0.0-0ubuntu2",
"binary_name": "glance"
},
{
"binary_version": "2:12.0.0-0ubuntu2",
"binary_name": "glance-api"
},
{
"binary_version": "2:12.0.0-0ubuntu2",
"binary_name": "glance-common"
},
{
"binary_version": "2:12.0.0-0ubuntu2",
"binary_name": "glance-glare"
},
{
"binary_version": "2:12.0.0-0ubuntu2",
"binary_name": "glance-registry"
},
{
"binary_version": "2:12.0.0-0ubuntu2",
"binary_name": "python-glance"
}
]
}