CVE-2014-0162
OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
EPSS 0.56%
Description
The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.
How to fix CVE-2014-0162
To remediate CVE-2014-0162, upgrade the affected package to a fixed version below.
- Debian/glance—upgrade to 2014.1-1 or later
- PyPI/glance—upgrade to 2013.2.4 or later
Is CVE-2014-0162 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2014.1-1
- >= 2013.2, < 2013.2.4