CVE-2022-4134: Low severity openstack glance store vulnerability
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
Other sources
https://wiki.openstack.org/wiki/OSSN/OSSN-0090
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4134?
CVE-2022-4134 is a vulnerability found in the OpenStack Glance software that allows a remote authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
How does CVE-2022-4134 impact OpenStack Glance?
CVE-2022-4134 allows a remote authenticated attacker to tamper with images, potentially compromising the integrity of virtual machines created with those modified images.
What is the severity of CVE-2022-4134?
The severity of CVE-2022-4134 is medium, with a CVSSv3 score of 2.8.
Which software versions are affected by CVE-2022-4134?
OpenStack Glance versions, Red Hat OpenStack versions 13, 16.1, 16.2, and 17 are affected by CVE-2022-4134.
How can I fix the CVE-2022-4134 vulnerability?
To fix the CVE-2022-4134 vulnerability, it is recommended to update OpenStack Glance to the latest version available and apply any patches or security updates provided by the software vendor.