MEDIUM · 6.0

CVE-2014-0162

The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or mo...

Vulnerability Description

The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.

CVSS Score

6.0

MEDIUM

AV:N/AC:M/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
OpenstackIcehouserc-1
OpenstackImage Registry And Delivery Service \(Glance\)2013.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-0162?

CVE-2014-0162 is a vulnerability with a CVSS score of 6.0 (MEDIUM). The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or mo...

How severe is CVE-2014-0162?

CVE-2014-0162 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-0162?

Check the references section above for vendor advisories and patch information. Affected products include: Openstack Icehouse, Openstack Image Registry And Delivery Service \(Glance\).