← Back

CVE-2026-34881

nvd nist
Published: Mar 31, 2026Modified: Apr 14, 2026

JSON object

Loading...
5.0
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Exploitability: 3.1 / Impact: 1.4
Source: MITRE (Secondary)

Description

OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.

Affected (3)

Products: Openstack: Glance
1 product
Glance
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Openstack
Before 29.1.1
From 30.0.0 to 30.1.1
Version 31.0.0

References (3)

Source: cve@mitre.org
ExploitIssue TrackingThird Party Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitIssue TrackingThird Party Advisory

Timeline

No history available yet.