| CVE-2015-5162 |
high |
7.5 |
7.5 |
|
|
|
10y ago |
The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attack… |
| CVE-2015-5163 |
low |
— |
3.5 |
|
|
|
11y ago |
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file… |
| CVE-2013-1840 |
low |
— |
3.5 |
|
|
|
13y ago |
The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obt… |
| CVE-2014-1948 |
low |
— |
2.6 |
|
|
|
4y ago |
OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARN… |