5.5
CVSSv2

CVE-2012-4573

Published: 11/11/2012 Updated: 29/08/2017
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P

Vulnerability Summary

The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack folsom 2012.2

openstack essex 2012.1

openstack image registry and delivery service \\(glance\\) -

Vendor Advisories

Synopsis Low: openstack-glance security update Type/Severity Security Advisory: Low Topic Updated openstack-glance packages that fix multiple bugs and add variousenhancements are now available for Red Hat OpenStack Essex Description The openstack-glance packages allows virtual machine imag ...
Debian Bug report logs - #692641 CVE-2012-4573: Authentication bypass for image deletion Package: glance; Maintainer for glance is Debian OpenStack <team+openstack@trackerdebianorg>; Source for glance is src:glance (PTS, buildd, popcon) Reported by: Thomas Goirand <zigo@debianorg> Date: Thu, 8 Nov 2012 03:45:01 U ...
Glance could be made to delete arbitrary images ...
Glance could be made to delete arbitrary images ...