CVE-2015-8234

MEDIUM

OpenStack Glance 11.0.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.

References (3)

Core 3
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2015/q4/303
Third Party Advisory x_refsource_confirm
https://wiki.openstack.org/wiki/OSSN/OSSN-0061
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugs.launchpad.net/glance/+bug/1516031

Scores

CVSS v3 5.5
EPSS 0.0032
EPSS Percentile 55.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-310
Status published
Products (2)
openstack/glance 11.0.0
pypi/glance 0PyPI
Published Mar 29, 2017
Tracked Since Feb 18, 2026