CVE

Id
76794  
CVE No.
CVE-2014-9493  
Status
Candidate  
Description
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.  
Phase
Assigned (20150103)  
Votes
None (candidate not yet proposed)  
Comments