An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible t…
中危 CVSS 5.8
摘要
An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'http://localhost:22'. This could then allow an attacker to enumerate internal network details while appearing masked, since the scan would appear to originate from the Glance Image service.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- http://www.securityfocus.com/bid/96988 Third Party Advisory
- https://bugs.launchpad.net/ossn/+bug/1153614 Third Party Advisory
- https://bugs.launchpad.net/ossn/+bug/1606495 Third Party Advisory
- https://wiki.openstack.org/wiki/OSSN/OSSN-0078 Vendor Advisory
- http://www.securityfocus.com/bid/96988 Third Party Advisory
- https://bugs.launchpad.net/ossn/+bug/1153614 Third Party Advisory
- https://bugs.launchpad.net/ossn/+bug/1606495 Third Party Advisory
- https://wiki.openstack.org/wiki/OSSN/OSSN-0078 Vendor Advisory
时间线
- nvd_ingest NVD