{"id":"PYSEC-2023-270","details":"A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.","aliases":["CVE-2022-4134","GHSA-5gp5-vxj6-4257"],"modified":"2026-07-01T20:22:53.366107Z","published":"2023-03-06T23:15:00Z","references":[{"type":"ADVISORY","url":"https://wiki.openstack.org/wiki/OSSN/OSSN-0090"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2147462"},{"type":"REPORT","url":"https://bugs.launchpad.net/glance/+bug/1990157"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5gp5-vxj6-4257"}],"affected":[{"package":{"name":"glance","ecosystem":"PyPI","purl":"pkg:pypi/glance"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"25.1.0"}]}],"versions":["15.0.2","17.0.1","18.0.0","18.0.0.0b1","18.0.0.0rc1","18.0.1","19.0.0","19.0.0.0b1","19.0.0.0rc1","19.0.0.0rc2","19.0.1","19.0.2","19.0.3","19.0.4","20.0.0","20.0.0.0b1","20.0.0.0b2","20.0.0.0b3","20.0.0.0rc1","20.0.0.0rc2","20.0.1","20.1.0","20.2.0","21.0.0","21.0.0.0b1","21.0.0.0b2","21.0.0.0rc1","21.0.0.0rc2","21.1.0","22.0.0","22.0.0.0b2","22.0.0.0b3","22.0.0.0rc1","22.1.0","22.1.1","23.0.0","23.0.0.0b2","23.0.0.0b3","23.0.0.0rc1","23.0.0.0rc2","23.1.0","24.0.0","24.0.0.0rc1","24.1.0","24.2.0","24.2.1","25.0.0","25.0.0.0b2","25.0.0.0b3","25.0.0.0rc1","25.1.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/glance/PYSEC-2023-270.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"}]}