Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-1840

Опубликовано: 14 мар. 2013
Источник: redhat
CVSS2: 3.5

Описание

The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 2.1openstack-glanceAffected
RHOS Essex Releaseopenstack-glanceAffected
OpenStack Folsom for RHEL 6openstack-glanceFixedRHSA-2013:070704.04.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=920393Glance: Backend credentials leak in Glance v1 API

3.5 Low

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.

nvd
почти 13 лет назад

The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.

debian
почти 13 лет назад

The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Gr ...

github
больше 3 лет назад

OpenStack Glance is vulnerable to Exposure of Sensitive Information

3.5 Low

CVSS2