{"id":"GHSA-5gp5-vxj6-4257","summary":"OpenStack Glance Inclusion of Functionality from Untrusted Control Sphere vulnerability","details":"A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.","aliases":["CVE-2022-4134","PYSEC-2023-270"],"modified":"2025-03-06T21:51:16.354866Z","published":"2023-03-07T00:30:24Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-03-08T00:16:31Z","nvd_published_at":"2023-03-06T23:15:00Z","cwe_ids":["CWE-829"],"severity":"LOW"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-0757"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-4134"},{"type":"WEB","url":"https://bugs.launchpad.net/glance/+bug/1990157"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2147462"},{"type":"PACKAGE","url":"https://github.com/openstack/glance"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/glance/PYSEC-2023-270.yaml"},{"type":"WEB","url":"https://wiki.openstack.org/wiki/OSSN/OSSN-0090"}],"affected":[{"package":{"name":"glance","ecosystem":"PyPI","purl":"pkg:pypi/glance"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"25.1.0"}]}],"versions":["15.0.2","17.0.1","18.0.0","18.0.0.0b1","18.0.0.0rc1","18.0.1","19.0.0","19.0.0.0b1","19.0.0.0rc1","19.0.0.0rc2","19.0.1","19.0.2","19.0.3","19.0.4","20.0.0","20.0.0.0b1","20.0.0.0b2","20.0.0.0b3","20.0.0.0rc1","20.0.0.0rc2","20.0.1","20.1.0","20.2.0","21.0.0","21.0.0.0b1","21.0.0.0b2","21.0.0.0rc1","21.0.0.0rc2","21.1.0","22.0.0","22.0.0.0b2","22.0.0.0b3","22.0.0.0rc1","22.1.0","22.1.1","23.0.0","23.0.0.0b2","23.0.0.0b3","23.0.0.0rc1","23.0.0.0rc2","23.1.0","24.0.0","24.0.0.0rc1","24.1.0","24.2.0","24.2.1","25.0.0","25.0.0.0b2","25.0.0.0b3","25.0.0.0rc1","25.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-5gp5-vxj6-4257/GHSA-5gp5-vxj6-4257.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"}]}