CVE-2016-4383: High severity openstack glance vulnerability
Published Jun 27, 2017
·Updated
The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated users to cause other users to boot into a modified image without notification of the change.
Affected Software
1 affected component
HP Helion Openstack Glance
Event History
Jun 27, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4383?
CVE-2016-4383 is classified as a medium severity vulnerability.
2
How do I fix CVE-2016-4383?
To mitigate CVE-2016-4383, update to the latest version of HPE Helion OpenStack Glance that addresses this issue.
3
Who is affected by CVE-2016-4383?
Any user of HPE Helion OpenStack Glance with the ability to manage images may be affected by CVE-2016-4383.
4
What types of systems are affected by CVE-2016-4383?
CVE-2016-4383 affects all versions of HPE Helion OpenStack Glance.
5
What is the impact of CVE-2016-4383 on users?
CVE-2016-4383 allows remote authenticated users to boot other users into modified images without notification.