CVE-2012-4573

OpenStack Glance <2012.2 - Auth Bypass

Title source: llm

Description

The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.

Scores

EPSS 0.0084
EPSS Percentile 74.5%

Classification

CWE
CWE-264
Status draft

Affected Products (4)

openstack/essex
openstack/folsom
openstack/image_registry_and_delivery_service_\(glance\)
pypi/glance < 11.0.0a0PyPI

Timeline

Published Nov 11, 2012
Tracked Since Feb 18, 2026