CVE-2013-4354: Input Validation
The API before 2.1 in OpenStack Image Registry and Delivery Service (Glance) makes it easier for local users to inject images into arbitrary tenants by adding the tenant as a member of the image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4354?
CVE-2013-4354 is considered to be of moderate severity due to its potential for unauthorized image injection.
How do I fix CVE-2013-4354?
To address CVE-2013-4354, upgrade to OpenStack Image Registry and Delivery Service (Glance) version 2.1 or later, which resolves this vulnerability.
What impact does CVE-2013-4354 have on OpenStack users?
CVE-2013-4354 allows local users to inject images into arbitrary tenants, potentially leading to unauthorized access to sensitive tenant data.
Which versions of OpenStack are affected by CVE-2013-4354?
CVE-2013-4354 affects all versions of OpenStack Image Registry and Delivery Service (Glance) prior to version 2.1.
Is there a known exploit for CVE-2013-4354?
As of now, no specific public exploits for CVE-2013-4354 have been documented, but the vulnerability presents a risk that could be exploited by knowledgeable users.