CyberRota Analysis
AI-GeneratedThe VMware datastore driver in OpenStack glance_store is vulnerable to an authentication header leakage due to improper validation of image location URIs. An authenticated attacker can exploit this flaw by supplying a crafted URI that points to an external server, potentially exposing sensitive authentication information. Organizations using VMware with OpenStack should prioritize patching this vulnerability to mitigate the risk of unauthorized access and data exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destination host before attaching sensitive authentication headers.