Bug 2459942 (CVE-2026-35587)
| Summary: | CVE-2026-35587 glances: Glances: Server-Side Request Forgery allows unauthorized access and credential leakage via public_api parameter | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Glances, an open-source system monitoring tool. An attacker with the ability to modify the Glances configuration can exploit a Server-Side Request Forgery (SSRF) vulnerability. This flaw, caused by improper validation of the `public_api` configuration parameter, allows the attacker to force the application to send requests to arbitrary internal or external network endpoints. This can lead to unauthorized access to internal services, retrieval of sensitive data, and potential leakage of credentials to attacker-controlled servers.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2460034, 2460037 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-04-21 00:02:29 UTC
|