The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.
| Score | Percentile |
|---|---|
| 1.40% | 79.86% |
No CVSS scores in this advisory.
| Type | Value |
|---|---|
| GHSA | GHSA-vwr9-9f8v-vp5m ↗ |
| CVE | CVE-2012-5482 ↗ |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| pip | glance | < 11.0.0a0 | 11.0.0a0 | — |