漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
OpenStack Glance 安全漏洞
Vulnerability Description
OpenStack Glance是Mirrors of opendev.org/openstack开源的一个虚拟机镜像存储与管理服务。 OpenStack Glance 29.1.1之前版本、30.0.0至30.1.1之前版本和31.0.0版本存在安全漏洞,该漏洞源于URL验证检查可被绕过,可能导致服务端请求伪造攻击。
CVSS Information
N/A
Vulnerability Type
N/A