The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.
2014-04-27T20:55:23.667
2025-04-12T10:46:40.837
Deferred
CVSSv2: 6.0 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openstack | icehouse | rc-1 | Yes |
Application | openstack | image_registry_and_delivery_service_\(glance\) | 2013.2 | Yes |
Application | openstack | image_registry_and_delivery_service_\(glance\) | 2013.2.1 | Yes |
Application | openstack | image_registry_and_delivery_service_\(glance\) | 2013.2.2 | Yes |
Application | openstack | image_registry_and_delivery_service_\(glance\) | 2013.2.3 | Yes |