Executive brief
The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.
Affected products
- PyPI glance
Junglewise Threat Intelligence
CVE-2015-8234 · Severity: low · CVSS 3 · Published 2017-03-29
Technologies: glance (PyPI). Vendors: PyPI.
The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.