CVE-2016-0757Medium· 4.3▾ SunlitOpenStack Image Service (Glance) vulnerable to Improper Access Control
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.5%
1.5% → 1.7%
OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by removing the last location of an image.
glance >= 11.0.0, < 11.0.2Upgrade to a patched release:
glance 11.0.2Connected by shared product, vendor, weakness, or advisory.
CVE-2014-0162MediumOpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
CVE-2015-5251MediumOpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions
CVE-2015-5286MediumOpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service
CVE-2026-34881Medium· 5.0OpenStack Glance is affected by Server-Side Request Forgery (SSRF)
CVE-2015-1881NoneOpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…
CVE-2014-9684NoneOpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…