CVE-2013-4428
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image… (CVE-2013-4428)
noneEPSS 3.1%
Description
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
Metrics
Severity
none
52.10
no public PoC known
86.9 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Published
2013-10-27 00:00 UTC
—
Affected operating systems
linux
canonical / ubuntu_linux12.10
linux
canonical / ubuntu_linux13.04
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
openstack
glance2012.2 – 2012.2.4
openstack
glance2013.1 – 2013.1.4
openstack
glance
References & sources
- http://rhn.redhat.com/errata/RHSA-2013-1525.htmlvendor-advisoryx_refsource_REDHAT
- http://www.ubuntu.com/usn/USN-2003-1vendor-advisoryx_refsource_UBUNTU
- https://launchpad.net/glance/+milestone/2013.1.4x_refsource_CONFIRM
- https://bugs.launchpad.net/glance/+bug/1235378x_refsource_CONFIRM
- http://www.openwall.com/lists/oss-security/2013/10/15/8mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/63159vdb-entryx_refsource_BID
- http://www.openwall.com/lists/oss-security/2013/10/16/9mailing-listx_refsource_MLIST
- https://bugs.launchpad.net/glance/+bug/1235226x_refsource_CONFIRM
- https://launchpad.net/glance/+milestone/2013.2x_refsource_CONFIRM
IDCVE-2013-4428