Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-77648

Опубликовано: 20 авг. 2026
Источник: redhat
CVSS3: 2.2

Описание

In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.

A flaw was found in OpenStack Glance. A privileged administrator could exploit a vulnerability in the /v2/tasks API by crafting a specific import task. This action bypasses security filtering, enabling the administrator to perform Server-Side Request Forgery (SSRF). As a result, an attacker could access and retrieve sensitive information from internal URLs within the Glance service network.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-glance-apiNot affected
Red Hat OpenStack Platform 18.0rhoso/openstack-glance-api-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2520853glance: OpenStack Glance: Server-Side Request Forgery allows internal URL access by administrators

2.2 Low

CVSS3

Связанные уязвимости

CVSS3: 2.2
ubuntu
28 дней назад

In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.

CVSS3: 2.2
nvd
28 дней назад

In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.

CVSS3: 2.2
debian
28 дней назад

In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=imp ...

CVSS3: 2.2
github
28 дней назад

In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.

2.2 Low

CVSS3