CVE-2012-5482: Openstack Essex

Medium severity, CVSS 5.5. EPSS: 2.7% chance of exploitation in the next 30 days.

The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4573.

Affected products

  • Openstack Essex: version 2012.1 only
  • Openstack Folsom: version 2012.2 only
  • Openstack Image Registry And Delivery Service (glance): affected versions not specified

Published 2012-11-11. Last modified 2026-06-16.