MEDIUM 5.5 PyPI
OpenStack Glance Signature Verification Bypass
GHSA-wmhw-fvg9-87fc · CVE-2015-8234 · PYSEC-2017-143
Published · Modified
Description
The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2015-8234
- WEB https://bugs.launchpad.net/glance/+bug/1516031
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/glance/PYSEC-2017-143.yaml
- WEB https://seclists.org/oss-sec/2015/q4/303
- WEB https://wiki.openstack.org/wiki/OSSN/OSSN-0061
- WEB http://seclists.org/oss-sec/2015/q4/303
Ready to move
Start Securing
Free, no credit card | First findings in minutes