All Glance deployments that use the web-download import method or the HTTP image location APIs are affected. The HTTP image location issue applies when the HTTP store is enabled.
For the web-download import method, an authenticated user can trigger requests to arbitrary internal URLs, including cloud metadata endpoints. The advisory does not state an authentication requirement for the HTTP image location API issue.
Yes. The web-download import method ships with insecure default filtering, which permits authenticated users to fetch arbitrary internal URLs. The HTTP image location API has no host filtering when the HTTP store is enabled.
Content fetched through the HTTP image location API is stored as image data and can be downloaded. This can turn an otherwise blind SSRF condition into full-read exfiltration of data retrieved from internal services.
Affected versions are Glance 16.0.0 through versions before 30.2.1, 31.0.0 through versions before 31.1.1, and 32.0.0 through versions before 32.0.1.