Show filters
38 Total Results
Displaying 1-10 of 38
Sort by:
Attacker Value
Unknown
CVE-2025-26570
Disclosure Date: February 13, 2025 (last updated February 14, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in uamv Glance That allows Cross Site Request Forgery. This issue affects Glance That: from n/a through 4.9.
0
Attacker Value
Unknown
CVE-2025-23792
Disclosure Date: January 27, 2025 (last updated January 28, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Busters Passwordless WP – Login with your glance or fingerprint allows Reflected XSS. This issue affects Passwordless WP – Login with your glance or fingerprint: from n/a through 1.1.6.
0
Attacker Value
Unknown
CVE-2024-32498
Disclosure Date: July 05, 2024 (last updated July 09, 2024)
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.
0
Attacker Value
Unknown
CVE-2024-1141
Disclosure Date: February 01, 2024 (last updated July 25, 2024)
A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level is enabled.
0
Attacker Value
Unknown
CVE-2022-4134
Disclosure Date: March 06, 2023 (last updated October 08, 2023)
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
0
Attacker Value
Unknown
CVE-2022-25937
Disclosure Date: February 13, 2023 (last updated November 08, 2023)
Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129).
0
Attacker Value
Unknown
CVE-2022-47951
Disclosure Date: January 26, 2023 (last updated October 08, 2023)
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data.
0
Attacker Value
Unknown
CVE-2022-31546
Disclosure Date: July 11, 2022 (last updated October 07, 2023)
The nlpweb/glance repository through 2014-06-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
0
Attacker Value
Unknown
CVE-2022-24696
Disclosure Date: March 13, 2022 (last updated October 07, 2023)
Mirametrix Glance before 5.1.1.42207 (released on 2018-08-30) allows a local attacker to elevate privileges. NOTE: this is unrelated to products from the glance.com and glance.net websites.
0
Attacker Value
Unknown
CVE-2021-23418
Disclosure Date: July 29, 2021 (last updated November 28, 2024)
The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is known to be vulnerable to XML attacks.
0