OSSA-2013-002: Backend password leak in Glance error message¶
- Date:
January 29, 2013
- CVE:
CVE-2013-0212
Affects¶
Glance: All versions
Description¶
Dan Prince of Red Hat discovered an issue in Glance error reporting. By creating an image in Glance by URL that references a mis-configured Swift endpoint, or if the Swift endpoint that a previously-ACTIVE image references for any reason becomes unusable, an authenticated user may access the Glance operator’s Swift credentials for that endpoint. Only setups that use the single-tenant Swift store are affected.
Patches¶
https://review.openstack.org/#/c/20695 (Grizzly)
Credits¶
Dan Prince from Red Hat (CVE-2013-0212)