PT-2026-49095 · Glance+1 · Glance+1
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Glances versions prior to 4.5.5
Description
The XML-RPC server (implemented in
glances/server.py and started with glances -s) fails to validate the HTTP Host header. This allows a DNS rebinding attack, where an attacker can bypass the same-origin policy to exfiltrate the complete system monitoring dataset through a victim's browser. DNS rebinding is a technique used to trick a browser into making requests to a local or private network resource by manipulating DNS records.Recommendations
Update to version 4.5.5.
Exploit
Fix
DoS
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Glance
Red Os