CVE-2014-0162
OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
EPSS 2.0%
Description
The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.
How to fix CVE-2014-0162
To remediate CVE-2014-0162, upgrade the affected package to a fixed version below.
- PyPI/glance—upgrade to 2013.2.4 or later
- PyPI/glance—upgrade to 2013.2.4 or later
Is CVE-2014-0162 being exploited?
Low — EPSS is 2.0%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 2013.2, < 2013.2.4
- >= 2013.2, < 2013.2.4