It was discovered that OpenStack Glance was incorrectly validating the IP addresses and the redirect destination URL when downloading or importing images from a remote source. An attacker could possibly use this issue to perform server-side request forgery and obtain sensitive information.
{
"binaries": [
{
"binary_version": "2:24.2.1-0ubuntu1.4",
"binary_name": "glance"
},
{
"binary_version": "2:24.2.1-0ubuntu1.4",
"binary_name": "glance-api"
},
{
"binary_version": "2:24.2.1-0ubuntu1.4",
"binary_name": "glance-common"
},
{
"binary_version": "2:24.2.1-0ubuntu1.4",
"binary_name": "python3-glance"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "2:28.1.0-0ubuntu1.2",
"binary_name": "glance"
},
{
"binary_version": "2:28.1.0-0ubuntu1.2",
"binary_name": "glance-api"
},
{
"binary_version": "2:28.1.0-0ubuntu1.2",
"binary_name": "glance-common"
},
{
"binary_version": "2:28.1.0-0ubuntu1.2",
"binary_name": "python3-glance"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "2:31.0.0-0ubuntu1.2",
"binary_name": "glance"
},
{
"binary_version": "2:31.0.0-0ubuntu1.2",
"binary_name": "glance-api"
},
{
"binary_version": "2:31.0.0-0ubuntu1.2",
"binary_name": "glance-common"
},
{
"binary_version": "2:31.0.0-0ubuntu1.2",
"binary_name": "python3-glance"
}
],
"availability": "No subscription required"
}