Show filters
38 Total Results
Displaying 31-38 of 38
Sort by:
Attacker Value
Unknown

CVE-2013-4354

Disclosure Date: November 23, 2013 (last updated October 05, 2023)
The API before 2.1 in OpenStack Image Registry and Delivery Service (Glance) makes it easier for local users to inject images into arbitrary tenants by adding the tenant as a member of the image.
0
Attacker Value
Unknown

CVE-2013-4428

Disclosure Date: October 27, 2013 (last updated October 05, 2023)
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
0
Attacker Value
Unknown

CVE-2013-4111

Disclosure Date: August 28, 2013 (last updated October 05, 2023)
The Python client library for Glance (python-glanceclient) before 0.10.0 does not properly check the preverify_ok value, which prevents the server hostname from being verified with a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate and allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0
Attacker Value
Unknown

CVE-2013-1840

Disclosure Date: March 22, 2013 (last updated October 05, 2023)
The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.
0
Attacker Value
Unknown

CVE-2013-0212

Disclosure Date: February 24, 2013 (last updated October 05, 2023)
store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.
0
Attacker Value
Unknown

CVE-2012-5482

Disclosure Date: November 11, 2012 (last updated October 05, 2023)
The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.
0
Attacker Value
Unknown

CVE-2012-4573

Disclosure Date: November 11, 2012 (last updated October 05, 2023)
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
0
Attacker Value
Unknown

CVE-2007-5178

Disclosure Date: October 03, 2007 (last updated October 04, 2023)
contrib/mx_glance_sdesc.php in the mx_glance 2.3.3 module for mxBB places a critical security check within a comment because of a missing comment delimiter, which allows remote attackers to conduct remote file inclusion attacks and execute arbitrary PHP code via a URL in the mx_root_path parameter. NOTE: some sources incorrectly state that phpbb_root_path is the affected parameter.
0