VYPR
Moderate severityNVD Advisory· Published Oct 26, 2015· Updated May 6, 2026

CVE-2015-5251

CVE-2015-5251

Description

OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
glancePyPI
>= 2011.2, < 2014.2.42014.2.4
glancePyPI
>= 2015.1.0, < 2015.1.22015.1.2

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.