CVE-2022-4134
published 2023-03-06CVE-2022-4134: A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual…
PriorityP411low2.8CVSS 3.1
AVLACLPRLUIRSUCNILAN
EPSS
0.32%
24.7th percentile
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| glance_project | glance | 0 – 25.1.0 | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.12.8LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
vendor_redhat2.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Glance Inclusion of Functionality from Untrusted Control Sphere vulnerability
ghsa·2023-03-07
CVE-2022-4134 [LOW] CWE-829 OpenStack Glance Inclusion of Functionality from Untrusted Control Sphere vulnerability
OpenStack Glance Inclusion of Functionality from Untrusted Control Sphere vulnerability
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
OSV
OpenStack Glance Inclusion of Functionality from Untrusted Control Sphere vulnerability
osv·2023-03-07
CVE-2022-4134 [LOW] OpenStack Glance Inclusion of Functionality from Untrusted Control Sphere vulnerability
OpenStack Glance Inclusion of Functionality from Untrusted Control Sphere vulnerability
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
OSV
CVE-2022-4134: A flaw was found in openstack-glance
osv·2023-03-06
CVE-2022-4134 CVE-2022-4134: A flaw was found in openstack-glance
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
Red Hat
openstack: glance & ceph conflict which allows image tampering
vendor_redhat·2022-10-14·CVSS 2.8
CVE-2022-4134 [LOW] CWE-829 openstack: glance & ceph conflict which allows image tampering
openstack: glance & ceph conflict which allows image tampering
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
Statement: You must be using Ceph as a backend to be affected by this flaw.
As this flaw would involve significant architectural changes, the impact is moderate. A fix will not be produced for Red Hat OpenStack Platform 16.2 and older releases. If you are concerned about the risk of this flaw against your environment, please follo
No detection rules found.
No public exploits indexed.
2023-03-06
Published