PT-2023-9099 · Openstack · Glance

Liran Tal

·

Publicado

2023-02-13

·

Atualizado

2025-03-21

·

CVE-2022-25937

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions glance versions prior to 3.0.9
Description The issue is related to a directory traversal vulnerability in the HTTP server of glance, allowing an attacker to bypass access restrictions and gain unauthorized access to protected information. This vulnerability enables users to read files outside the public root directory.
Recommendations For versions prior to 3.0.9, update to version 3.0.9 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-03603
CVE-2022-25937
GHSA-3HJH-5HGX-F5WH

Produtos afetados

Glance