CVE-2017-7200
Executive Summary
CVE-2017-7200 exposes a Server‑Side Request Forgery (SSRF) flaw in OpenStack Glance’s copy_from API (v1). An attacker can craft image URLs pointing to internal hosts (e.g., http://localhost:22), causing Glance to initiate requests from within the cloud environment. This enables masked internal network port scans and enumeration of internal services, potentially revealing sensitive topology while appearing to originate from the Glance service itself.
Authoritative CVE Metadata - CVSS Base Score: 5.8 (MEDIUM) - Published: 2017-03-21T06:59:00.227 - Last Modified: 2026-09-17T13:59:34.053
Original Description: An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'http://localhost:22'. This could then allow an attacker to enumerate internal network details while appearing masked, since the scan would appear to originate from the Glance Image service.
"If we learn to open our hearts, anyone, including the people who drive us crazy, can be our teacher."
— Pema Chodron