Moderate severityNVD Advisory· Published Apr 27, 2014· Updated May 6, 2026
CVE-2014-0162
CVE-2014-0162
Description
The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
glancePyPI | >= 2013.2, < 2013.2.4 | 2013.2.4 |
Affected products
5cpe:2.3:a:openstack:image_registry_and_delivery_service_\(glance\):2013.2:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:openstack:image_registry_and_delivery_service_\(glance\):2013.2:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:image_registry_and_delivery_service_\(glance\):2013.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:image_registry_and_delivery_service_\(glance\):2013.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:image_registry_and_delivery_service_\(glance\):2013.2.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- github.com/advisories/GHSA-r7pj-rvwg-vxhrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2014-0162ghsaADVISORY
- rhn.redhat.com/errata/RHSA-2014-0455.htmlnvdWEB
- www.openwall.com/lists/oss-security/2014/04/10/13nvdWEB
- www.ubuntu.com/usn/USN-2193-1nvdWEB
- access.redhat.com/errata/RHSA-2014:0455ghsaWEB
- access.redhat.com/security/cve/CVE-2014-0162ghsaWEB
- bugzilla.redhat.com/show_bug.cgighsaWEB
- launchpad.net/bugs/1298698nvdWEB
- opendev.org/openstack/glanceghsaPACKAGE
News mentions
0No linked articles in our index yet.