High severityNVD Advisory· Published Aug 19, 2015· Updated Jun 17, 2026
CVE-2015-5163
CVE-2015-5163
Description
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
glancePyPI | >= 2015.1.0, < 2015.1.2 | 2015.1.2 |
Affected products
3Patches
Vulnerability mechanics
References
12- github.com/advisories/GHSA-q73f-vjc2-3gqfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2015-5163ghsaADVISORY
- lists.openstack.org/pipermail/openstack-announce/2015-August/000527.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2015-1639.htmlnvdWEB
- access.redhat.com/errata/RHSA-2015:1639ghsaWEB
- access.redhat.com/security/cve/CVE-2015-5163ghsaWEB
- bugs.launchpad.net/glance/+bug/1471912nvdWEB
- bugzilla.redhat.com/show_bug.cgighsaWEB
- github.com/openstack/glance/commit/eb99e45829a1b4c93db5692bdbf636a86faa56c4ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/glance/PYSEC-2015-39.yamlghsaWEB
- web.archive.org/web/20200228024903/http://www.securityfocus.com/bid/76346ghsaWEB
- www.securityfocus.com/bid/76346nvd
News mentions
0No linked articles in our index yet.