{"id":"CVE-2014-0162","aliases":["GHSA-r7pj-rvwg-vxhr","PYSEC-2026-817"],"title":"OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability","summary":"OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability","severity":"medium","vendor":"glance","product":"glance","ecosystem":"pip","affected":["glance >= 2013.2, < 2013.2.4"],"patched":["glance 2013.2.4"],"published":"2022-05-17","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-r7pj-rvwg-vxhr","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0162"},{"url":"https://access.redhat.com/errata/RHSA-2014:0455"},{"url":"https://access.redhat.com/security/cve/CVE-2014-0162"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1085163"},{"url":"https://launchpad.net/bugs/1298698"},{"url":"https://opendev.org/openstack/glance"},{"url":"http://rhn.redhat.com/errata/RHSA-2014-0455.html"},{"url":"http://www.openwall.com/lists/oss-security/2014/04/10/13"},{"url":"http://www.ubuntu.com/usn/USN-2193-1"}],"tags":["osv","pip"],"epss":0.01992,"epssPercentile":0.79551,"ingestedAt":"2026-07-08T18:25:52.675Z","slug":"CVE-2014-0162","body":"## Overview\n\nThe Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.\n\n## Affected packages\n\n- `glance >= 2013.2, < 2013.2.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `glance 2013.2.4`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}