Source: glance Version: 2:30.0.0-3+deb13u2 Severity: important Tags: patch security X-Debbugs-Cc: Debian Security Team <[email protected]>
As per upstream announce at: https://wiki.openstack.org/wiki/OSSN/OSSN-0105 Glance legacy Tasks import bypasses image import URI filtering Summary The deprecated Glance /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (SSRF). The tasks API has been admin-only since Xena and deprecated for several releases. Affected Services / Software: glance: >=30.0.0 <30.3.0, >=31.0.0 <31.1.1, ==32.0.0 Discussion: The legacy tasks import path uses a permissive URI validator that only checks for http:// or https:// prefixes, bypassing the host and port restrictions enforced by the modern web-download import. Recommended Actions: Disable the legacy tasks API via policy if you are not using it. Otherwise, upgrade Glance to a version containing the fix. Patches: The following reviews contain the fix for this issue: 2026.2/hibiscus (development): https://review.opendev.org/c/openstack/glance/+/993588 2026.1/gazpacho: https://review.opendev.org/c/openstack/glance/+/994466 2025.2/flamingo: https://review.opendev.org/c/openstack/glance/+/994592 2025.1/epoxy: https://review.opendev.org/c/openstack/glance/+/1000061 Credits: Tim Shephard, roiai.ca Contacts / References Authors: Goutham Pacha Ravi, Red Hat This OSSN: https://wiki.openstack.org/wiki/OSSN/OSSN-0105 Original Launchpad bug: https://bugs.launchpad.net/glance/+bug/2152110 Mailing List : [security-sig] tag on [email protected] OpenStack Security : https://security.openstack.org/ CVE: none

