The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated users to cause other users to boot into a modified image without notification of the change.
2017-06-27T20:29:00.840
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 8.4 (HIGH)
AV:N/AC:M/Au:S/C:C/I:C/A:C
6.8
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | hp | helion_openstack_glance | - | Yes |