Описание
The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.
A flaw was found in OpenStack Glance. Remote authenticated users can exploit this vulnerability by requesting a cached image when the single-tenant Swift or S3 store is in use. This action causes the system to report the location field, which can lead to the disclosure of the operator's backend credentials.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenStack Platform 16.2 | openstack-glance | Not affected | ||
| Red Hat OpenStack Platform 17.1 | openstack-glance | Not affected | ||
| Red Hat OpenStack Platform 18.0 | openstack-glance | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.
The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.
The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Gr ...
OpenStack Glance is vulnerable to Exposure of Sensitive Information
EPSS
6.5 Medium
CVSS3