CVE-2012-4573Project Glance vulnerability

CWE-26415 documents8 sources
Severity
5.5MEDIUMNVD
EPSS
0.8%
top 25.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 11
Latest updateMay 17

Description

The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 8.0 | Impact: 4.9

Affected Packages4 packages

NVDopenstack/essex2012.1
NVDopenstack/folsom2012.2
PyPIglance_project/glance< 11.0.0a0+2
Debianglance_project/glance< 2012.1.1-2+3

Patches

🔴Vulnerability Details

6
OSV
OpenStack Glance arbitrary deletion of non-protected images2022-05-17
GHSA
OpenStack Glance arbitrary deletion of non-protected images2022-05-17
GHSA
OpenStack Glance arbitrary deletion of non-protected images2022-05-17
OSV
CVE-2012-4573: The v2 API in OpenStack Glance Grizzly, Folsom (20122012-11-11
CVEList
CVE-2012-4573: The v1 API in OpenStack Glance Grizzly, Folsom (20122012-11-11

📋Vendor Advisories

4
Ubuntu
Glance vulnerability2012-11-09
Ubuntu
Glance vulnerability2012-11-08
Red Hat
OpenStack: Glance Authentication bypass for image deletion2012-11-07
Debian
CVE-2012-4573: glance - The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allo...2012

💬Community

4
Bugzilla
CVE-2012-4573, CVE-2012-5482 OpenStack: Glance Authentication bypass for image deletion [fedora-all]2012-11-08
Bugzilla
CVE-2012-4573, CVE-2012-5482 OpenStack: Glance Authentication bypass for image deletion [epel-6]2012-11-08
Bugzilla
CVE-2012-4573 OpenStack: Glance Authentication bypass for image deletion2012-11-01
Bugzilla
CVE-2011-4573 JON: Incorrect delete permissions check2011-12-05
CVE-2012-4573 — Glance Project Glance vulnerability | cvebase