An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker...
zetlyn/cve-ghsa vulnerability ghsa GHSA-p93m-62q2-q66v cve CVE-2026-51773 known 2026-09-25
https://github.com/advisories/GHSA-p93m-62q2-q66v
Properties
| cvss | 8.1receipt
This source has not kept a receipt for this claim yet. The next update that reads it will. |
|---|---|
| cwe | CWE-918receipt
This source has not kept a receipt for this claim yet. The next update that reads it will. |
| severity | high From 7.0 to 8.9. receipt
This source has not kept a receipt for this claim yet. The next update that reads it will. |
Text
An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker...
An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destination host before attaching sensitive authentication headers.