CVE Vulnerabilities

CVE-2014-9493

Published: Jan 07, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:P
RedHat/V2
5.5 IMPORTANT
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.

Affected Software

NameVendorStart VersionEnd Version
OpenstackRedhat4.0 (including)4.0 (including)
OpenstackRedhat5.0 (including)5.0 (including)
OpenStack 4 for RHEL 6RedHatopenstack-glance-0:2013.2.4-3.el6ost*
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6RedHatopenstack-glance-0:2014.1.3-4.el6ost*
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7RedHatopenstack-glance-0:2014.1.3-4.el7ost*
GlanceUbuntutrusty*

References