SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-9493

The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.

MEDIUM 5.5EPSS 2.79%

Does this matter?

Lower severity and a low EPSS score (2.79%). Track it; it rarely justifies an emergency change on its own.

Description

The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.

CVSS 2.0
5.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
EPSS
2.79% probability · 86th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
redhat/openstack · openstack/image registry and delivery service \(glance\)
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.