Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. glance
  4. ›
  5. CVE-2022-47951

CVE-2022-47951: OpenStack Cinder, glance, and Nova vulnerable to Path Traversal

January 27, 2023 (updated March 31, 2025)

An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file’s contents from the server, resulting in unauthorized access to potentially sensitive data.

References

  • github.com/advisories/GHSA-7h75-hwxx-qpgc
  • launchpad.net/bugs/1996188
  • lists.debian.org/debian-lts-announce/2023/01/msg00040.html
  • lists.debian.org/debian-lts-announce/2023/01/msg00041.html
  • lists.debian.org/debian-lts-announce/2023/01/msg00042.html
  • nvd.nist.gov/vuln/detail/CVE-2022-47951
  • security.openstack.org/ossa/OSSA-2023-002.html
  • www.debian.org/security/2023/dsa-5336
  • www.debian.org/security/2023/dsa-5337
  • www.debian.org/security/2023/dsa-5338

Code Behaviors & Features

Detect and mitigate CVE-2022-47951 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 23.0.1, all versions starting from 24.0.0 before 24.1.1

Fixed versions

  • 23.0.1
  • 24.1.1

Solution

Upgrade to versions 23.0.1, 24.1.1 or above.

Impact 5.7 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Source file

pypi/glance/CVE-2022-47951.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:27 +0000.