ZeroHour

CVE-2016-0757

CVSS 3.0
4.3 medium
EPSS
1%p72
Published
()
Modified
Description

OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by removing the last location of an image.

Vendors
openstack
Products
image registry and delivery service \(glance\)
Weakness
CWE-284
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.