Medium severity5.8NVD Advisory· Published Mar 21, 2017· Updated Jun 17, 2026
CVE-2017-7200
CVE-2017-7200
Description
An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'http://localhost:22'. This could then allow an attacker to enumerate internal network details while appearing masked, since the scan would appear to originate from the Glance Image service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
glancePyPI | < 11.0.0a0 | 11.0.0a0 |
Affected products
2Patches
Vulnerability mechanics
References
7- www.securityfocus.com/bid/96988nvdThird Party AdvisoryVDB EntryWEB
- bugs.launchpad.net/ossn/+bug/1153614nvdThird Party AdvisoryWEB
- bugs.launchpad.net/ossn/+bug/1606495nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-j6mr-cm6x-h6jgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-7200ghsaADVISORY
- wiki.openstack.org/wiki/OSSN/OSSN-0078nvdVendor AdvisoryWEB
- github.com/openstack/glance/commit/b1ac90f7914d91b25144cc4063fa994fb5019ee3ghsaWEB
News mentions
0No linked articles in our index yet.