Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that
bypass import_filtering_opts, allowing an admin to fetch internal
URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
OpenStack Glance 服务端请求伪造漏洞
Vulnerability Description
OpenStack Glance是OpenStack基金会开源的一个镜像服务组件。 OpenStack Glance 32.0.0及之前版本存在服务端请求伪造漏洞,该漏洞源于/v2/tasks API接受type=import任务时绕过import_filtering_opts,允许管理员获取Glance服务网络的内部URL,造成服务端请求伪造(SSRF)。
CVSS Information
N/A
Vulnerability Type
N/A