在 OpenStack Glance 32.0.1 之前的版本中,location API 在将 HTTP 位置添加到镜像时,不会校验目标主机。与 web-download 导入路径不同,location API 仅检查 URL 协议,而不会应用 中的主机限制。经过认证的用户可以添加一个指向内部端点(例如云元数据服务 169.254.169.254)的位置,并通过下载镜像数据来获取响应。该问题同时影响新的 API 以及在启用 时的旧版 PATCH API。启用 HTTP 存储后端的部署环境均受此问题影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet