CVE-2016-0757

EUVD-2022-2682
OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by removing the last location of an image.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
Affected Products (NVD)
VendorProductVersion
openstackimage_registry_and_delivery_service_\(glance\)
11.0.0
openstackimage_registry_and_delivery_service_\(glance\)
11.0.1
openstackimage_registry_and_delivery_service_\(glance\)
2015.1.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
glance
bookworm
2:25.1.0-2+deb12u1
fixed
bookworm (security)
2:25.1.0-2+deb12u1
fixed
bullseye
2:21.0.0-2+deb11u1
fixed
bullseye (security)
2:21.1.0-1+deb11u2
fixed
jessie
no-dsa
sid
2:29.0.0-1
fixed
trixie
2:29.0.0-1
fixed
wheezy
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
glance
precise
ignored
trusty
Fixed 1:2014.1.5-0ubuntu1.1
released
wily
ignored
xenial
not-affected
yakkety
not-affected
zesty
not-affected