Impact
The Glance service allows an authenticated user to add a URL as an image location when the HTTP store backend is enabled. The validation logic only checks the URL scheme, ignoring the host or IP address, which permits the server to issue requests to arbitrary internal network services. This full‑read SSRF can expose sensitive data such as cloud metadata credentials, leading to a compromise of confidential information.
Affected Systems
Version information is not disclosed, so the vulnerability applies to any deployment of OpenStack Glance that uses the HTTP store backend. The affected software is the OpenStack Glance component, where users can insert image locations via the location API.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity with potential for serious impact if exploited. Since an attacker must be authenticated and the exploit requires only an internal URL, the risk is moderate but the potential damage is significant. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, meaning it may not yet have known public exploits but still requires immediate attention.
OpenCVE Enrichment