Vulnerability Name: | CVE-2013-1840 (CCN-82878) | ||||||||||||||||
Assigned: | 2013-03-14 | ||||||||||||||||
Published: | 2013-03-14 | ||||||||||||||||
Updated: | 2017-08-29 | ||||||||||||||||
Summary: | The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image. | ||||||||||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N/E:H/RL:OF/RC:C)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:H/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-1840 Source: CCN Type: OpenStack Glance Web Site OpenStack Glance Source: OSVDB Type: UNKNOWN 91304 Source: REDHAT Type: UNKNOWN RHSA-2013:0707 Source: CCN Type: SA52565 OpenStack Glance Backend Information Disclosure Security Issue Source: SECUNIA Type: Vendor Advisory 52565 Source: MLIST Type: UNKNOWN [oss-security] 20130314 [OSSA 2013-007] Backend credentials leak in Glance v1 API (CVE-2013-1840) Source: BID Type: UNKNOWN 58490 Source: CCN Type: BID-58490 OpenStack Glance CVE-2013-1840 Information Disclosure Vulnerability Source: UBUNTU Type: UNKNOWN USN-1764-1 Source: CCN Type: OpenStack Image Registry and Delivery Service (Glanc) Web Site v1 api returns location as header for cached images Source: CONFIRM Type: UNKNOWN https://bugs.launchpad.net/glance/+bug/1135541 Source: XF Type: UNKNOWN openstack-glance-api-info-disclosure(82878) Source: XF Type: UNKNOWN openstack-glance-api-info-disclosure(82878) Source: CCN Type: OSSA 2013-007 Backend credentials leak in Glance v1 API (CVE-2013-1840) Source: CONFIRM Type: UNKNOWN https://review.openstack.org/#/c/24437/ Source: CONFIRM Type: UNKNOWN https://review.openstack.org/#/c/24438/ Source: CONFIRM Type: UNKNOWN https://review.openstack.org/#/c/24439/ | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |