CVE-2013-4428

OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:glance:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:glance:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:glance:2013.2:milestone1:*:*:*:*:*:*
cpe:2.3:a:openstack:glance:2013.2:milestone2:*:*:*:*:*:*
cpe:2.3:a:openstack:glance:2013.2:milestone3:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*

History

No history.

Information

Published : 2013-10-27 00:55

Updated : 2023-12-10 11:16


NVD link : CVE-2013-4428

Mitre link : CVE-2013-4428

CVE.ORG link : CVE-2013-4428


JSON object : View

Products Affected

canonical

  • ubuntu_linux

openstack

  • glance
CWE
CWE-264

Permissions, Privileges, and Access Controls