← Vulnerability feed

Vulnerability record · CVE-2012-4573 · published 11 November 2012

CVE-2012-4573: Openstack essex permissions and access controls vulnerability

Openstack · Essex

The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.

5.5 CVSS 2.0 Medium EPSS 3.3% · top 11.8% CWE-264 · Permissions and access controls
5.5CVSS 2.0 base score
3.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
34References
16 Jun 2026Last modified by NVD

Description

The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.

AV:N/AC:L/Au:S/C:N/I:P/A:P

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092192.html
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00002.html
http://osvdb.org/87248
http://packetstormsecurity.com/files/118733/Red-Hat-Security-Advisory-2012-1558-01.html
http://rhn.redhat.com/errata/RHSA-2012-1558.html
http://secunia.com/advisories/51174 Vendor Advisory
http://secunia.com/advisories/51234 Vendor Advisory
http://www.openwall.com/lists/oss-security/2012/11/07/6
http://www.openwall.com/lists/oss-security/2012/11/09/5
http://www.securityfocus.com/bid/56437
http://www.ubuntu.com/usn/USN-1626-1
http://www.ubuntu.com/usn/USN-1626-2
https://bugs.launchpad.net/glance/+bug/1065187
https://exchange.xforce.ibmcloud.com/vulnerabilities/79895
https://github.com/openstack/glance/commit/6ab0992e5472ae3f9bef0d2ced41030655d9d2bc
https://github.com/openstack/glance/commit/90bcdc5a89e350a358cf320a03f5afe99795f6f6
https://github.com/openstack/glance/commit/efd7e75b1f419a52c7103c7840e24af8e5deb29d Patch
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092192.html
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00002.html
http://osvdb.org/87248
http://packetstormsecurity.com/files/118733/Red-Hat-Security-Advisory-2012-1558-01.html
http://rhn.redhat.com/errata/RHSA-2012-1558.html
http://secunia.com/advisories/51174 Vendor Advisory
http://secunia.com/advisories/51234 Vendor Advisory
http://www.openwall.com/lists/oss-security/2012/11/07/6
http://www.openwall.com/lists/oss-security/2012/11/09/5
http://www.securityfocus.com/bid/56437
http://www.ubuntu.com/usn/USN-1626-1
http://www.ubuntu.com/usn/USN-1626-2
https://bugs.launchpad.net/glance/+bug/1065187
https://exchange.xforce.ibmcloud.com/vulnerabilities/79895
https://github.com/openstack/glance/commit/6ab0992e5472ae3f9bef0d2ced41030655d9d2bc
https://github.com/openstack/glance/commit/90bcdc5a89e350a358cf320a03f5afe99795f6f6
https://github.com/openstack/glance/commit/efd7e75b1f419a52c7103c7840e24af8e5deb29d Patch

Track CVE-2012-4573 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2013-0261Openstack essex link following vulnerabilityA flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This …EPSS 0.34%7.6CVE-2013-0335Openstack essex insufficient session expiration vulnerabilityOpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circu…EPSS 2.1%7.5CVE-2013-2161Openstack folsom code injection vulnerabilityXML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift r…EPSS 1.9%6.8CVE-2015-5286Openstack image registry and delivery service \(glance\) permissions and access controls vulnerabilityOpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage q…EPSS 2.4%6.8CVE-2013-1865Openstack folsom improper authentication vulnerabilityOpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remot…EPSS 2.6%6.5CVE-2015-1195Openstack image registry and delivery service \(glance\) path traversal vulnerabilityThe V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users t…EPSS 2.8%6.5CVE-2013-0208Openstack essex permissions and access controls vulnerabilityThe boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from ot…EPSS 2.5%6.4CVE-2013-4497Openstack havana permissions and access controls vulnerabilityThe XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2012-4573), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.