First published: Tue Jun 27 2017(Updated: )
The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated users to cause other users to boot into a modified image without notification of the change.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Glance |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4383 is classified as a medium severity vulnerability.
To mitigate CVE-2016-4383, update to the latest version of HPE Helion OpenStack Glance that addresses this issue.
Any user of HPE Helion OpenStack Glance with the ability to manage images may be affected by CVE-2016-4383.
CVE-2016-4383 affects all versions of HPE Helion OpenStack Glance.
CVE-2016-4383 allows remote authenticated users to boot other users into modified images without notification.