CVE-2022-4134
Publication date 6 March 2023
Last updated 11 July 2025
Ubuntu priority
Cvss 3 Severity Score
Description
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
Mitigation
See upstream recommendations at https://wiki.openstack.org/wiki/OSSN/OSSN-0090
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| glance | 26.04 LTS resolute |
Vulnerable, fix deferred
|
| 25.10 questing |
Vulnerable, fix deferred
|
|
| 24.04 LTS noble |
Vulnerable, fix deferred
|
|
| 22.04 LTS jammy |
Vulnerable, fix deferred
|
|
| 20.04 LTS focal |
Vulnerable, fix deferred
|
|
| 18.04 LTS bionic |
Vulnerable, fix deferred
|
|
| 16.04 LTS xenial |
Vulnerable, fix deferred
|
|
| 14.04 LTS trusty | Ignored end of standard support |
Notes
mdeslaur
as of 2022-11-29, there is no software fix for this issue, the recommended best practices to mitigate the issue is listed in the upstream OSSN. Marking CVE as deferred.
Severity score breakdown
CVSS version: CVSS v3.0
Base score
2.8 · Low
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N