Vulnerabilities > Openstack > Glance

DATE CVE VULNERABILITY TITLE RISK
2024-07-05 CVE-2024-32498 Unspecified vulnerability in Openstack Nova
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3.
network
low complexity
openstack
6.5
2023-03-06 CVE-2022-4134 Inclusion of Functionality from Untrusted Control Sphere vulnerability in multiple products
A flaw was found in openstack-glance.
local
low complexity
openstack redhat CWE-829
2.8
2023-01-26 CVE-2022-47951 Path Traversal vulnerability in multiple products
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0.
network
low complexity
openstack debian CWE-22
5.7
2018-07-31 CVE-2016-8611 Resource Exhaustion vulnerability in Openstack Glance
A vulnerability was found in Openstack Glance.
network
low complexity
openstack CWE-400
6.5
2017-03-29 CVE-2015-8234 Cryptographic Issues vulnerability in Openstack Glance 11.0.0
The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.
local
low complexity
openstack CWE-310
5.5
2017-03-21 CVE-2017-7200 Server-Side Request Forgery (SSRF) vulnerability in Openstack Glance
An SSRF issue was discovered in OpenStack Glance before Newton.
network
low complexity
openstack CWE-918
5.8
2016-10-07 CVE-2015-5162 Resource Management Errors vulnerability in Openstack Cinder, Glance and Nova
The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.
network
low complexity
openstack CWE-399
7.5