GHSA-p93m-62q2-q66vHighCVSS 8.1

An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker...

Published
September 25, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (1)

📋 Description

An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destination host before attaching sensitive authentication headers.

🔗 References (4)