Skip to main content

Vendor/product archive

openstack / glance CVEs

Beta · best-effort

12 CVEs tagged to openstack / glance0 Critical, 1 High, 7 Medium, 4 Low, 0 Unrated.

CVE-2026-34881

Published Mar 31, 2026

OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL va…

CVSS 5.0 · Medium
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2022-4134

Published Mar 6, 2023

A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using t…

CVSS 2.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-8611

Published Jul 31, 2018

A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2 `/images` API POST method for authenticated users, resulti…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8234

Published Mar 29, 2017

The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7200

Published Mar 21, 2017

An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5163

Published Aug 19, 2015

The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-3289

Published Aug 14, 2015

OpenStack Glance before 2015.1.1 (kilo) allows remote authenticated users to cause a denial of service (disk consumption) by repeatedly using the import task flow API to create im…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4428

Published Oct 27, 2013

OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly r…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1