PT-2023-9099 · Openstack · Glance

Liran Tal

·

Published

2023-02-13

·

Updated

2025-03-21

·

CVE-2022-25937

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions glance versions prior to 3.0.9
Description The issue is related to a directory traversal vulnerability in the HTTP server of glance, allowing an attacker to bypass access restrictions and gain unauthorized access to protected information. This vulnerability enables users to read files outside the public root directory.
Recommendations For versions prior to 3.0.9, update to version 3.0.9 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03603
CVE-2022-25937
GHSA-3HJH-5HGX-F5WH

Affected Products

Glance