VDB
CVE-2012-4573
CVE-2012-4573
PUBLISHED
CVSS 5.5 MEDIUM
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
EPSS 3.35% · 87.5th percentile
Risk Scores
CVSS 2.0
5.5
EPSS Score
3.35%
87.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| openstack | essex | 2012.1 |
| openstack | folsom | 2012.2 |
| openstack | image_registry_and_delivery_service_\(glance\) | |
| PyPI | glance | 0 |
| n/a | n/a | n/a |
Timeline
- Nov 11, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- 51174 third-party-advisory
- RHSA-2012:1558 vendor-advisory
- https://github.com/openstack/glance/commit/90bcdc5a89e350a358cf320a03f5afe99795f6f6 url
- [oss-security] 20121107 [OSSA 2012-017] Authentication bypass for image deletion (CVE-2012-4573) mailing-list
- [oss-security] 20121109 [OSSA 2012-017.1] Authentication bypass for image deletion (CVE-2012-4573, CVE-2012-5482) ERRATA 1 mailing-list
- http://packetstormsecurity.com/files/118733/Red-Hat-Security-Advisory-2012-1558-01.html url
- https://github.com/openstack/glance/commit/6ab0992e5472ae3f9bef0d2ced41030655d9d2bc url
- USN-1626-2 vendor-advisory
- https://github.com/openstack/glance/commit/efd7e75b1f419a52c7103c7840e24af8e5deb29d url
- 51234 third-party-advisory
- USN-1626-1 vendor-advisory
- 56437 vdb
- FEDORA-2012-17901 vendor-advisory
- 87248 vdb
- https://bugs.launchpad.net/glance/+bug/1065187 url
- SUSE-SU-2012:1455 vendor-advisory
- openstack-glance-sec-bypass(79895) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2012-4573 advisory
- https://github.com/openstack/glance package
- https://github.com/pypa/advisory-database/tree/main/vulns/glance/PYSEC-2012-29.yaml url