CVE-2016-0757: Openstack Image Registry And Delivery Service (glance)
Medium severity, CVSS 4.3. EPSS: 1.5% chance of exploitation in the next 30 days.
OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by removing the last location of an image.
Affected products
- Openstack Image Registry And Delivery Service (glance): version 11.0.0 only; version 11.0.1 only; version 2015.1.2 only
Published 2016-04-13. Last modified 2026-06-17.