CVE Vulnerabilities

CVE-2014-9493

Published: Jan 07, 2015 | Modified: Feb 01, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.

Affected Software

Name Vendor Start Version End Version
Openstack Redhat 4.0 4.0
Openstack Redhat 5.0 5.0

References