{"id":"CVE-2016-0757","aliases":["GHSA-5xrj-ghhp-hx7p","PYSEC-2026-811"],"url":"https://o3.security/vulnerability/CVE-2016-0757","summary":"OpenStack Image Service (Glance) vulnerable to Improper Access Control","details":"OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by removing the last location of an image.","published":"2016-04-13T17:59:09.867Z","modified":"2026-07-08T12:35:41.577025Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"},"epss":{"score":0.01466,"percentile":0.71677,"asOf":"2026-08-22"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"glance","fixedVersion":"11.0.2"}],"fix":null,"references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/82696"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-0309.html"},{"type":"FIX","url":"https://security.openstack.org/ossa/OSSA-2016-006.html"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-0757"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2016:0309"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2016:0352"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2016:0354"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2016:0358"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2016-0757"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1302607"},{"type":"PACKAGE","url":"https://opendev.org/openstack/glance"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2016-0309.html"},{"type":"WEB","url":"https://web.archive.org/web/20210123081823/https://www.securityfocus.com/bid/82696"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:35:41.577025Z"}}