I do not see that this has anything to do with the Glance v1->v2 work in Nova. Nova does not allow creating images with custom locations or updating an image location so it is not an attack vector here.
Nova is dependent on Glance v1 currently and is a reason that it can't be thrown in a fire and this vulnerability ignored, but it is not the only reason that Glance v1 still exists and should be fixed.
I do not see that this has anything to do with the Glance v1->v2 work in Nova. Nova does not allow creating images with custom locations or updating an image location so it is not an attack vector here.
Nova is dependent on Glance v1 currently and is a reason that it can't be thrown in a fire and this vulnerability ignored, but it is not the only reason that Glance v1 still exists and should be fixed.