CVE-2017-7200Medium· 5.8▾ SunlitAn SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'ht…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.9 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
2.0%
2.0% → 2.2%
Last analysed / modified upstream
An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'http://localhost:22'. This could then allow an attacker to enumerate internal network details while appearing masked, since the scan would appear to originate from the Glance Image service.
glance < 11.0.0Upgrade past the affected range:
glance 11.0.0Affected packages:
glance < 11.0.0a0Patched in:
glance 11.0.0a0Source: https://osv.dev/vulnerability/GHSA-j6mr-cm6x-h6jg
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34881Medium· 5.0OpenStack Glance is affected by Server-Side Request Forgery (SSRF)
CVE-2015-1195MediumOpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme
CVE-2014-9623MediumOpenStack Glance Bypass the storage quota and Denial of service
CVE-2014-5356MediumOpenStack Glance improper validation of the image_size_cap configuration option
CVE-2026-43003High· 8.0An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0
CVE-2026-71198High· 7.0In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image