LOW
Glance: image_download policy not enforced for cached images
Published Oct 27, 2013
3.5
LOWCVSS 2.0
EPSS 3.08%
Description
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
Affected products
No data.
Configuration 1
Configuration 2
OR
- 12.10
- 13.04
No data.
OpenStack 3 for RHEL 6
openstack-glance-0:2013.1.4-1.el6ost
Fixed · RHSA-2013:1525
Red Hat OpenStack Platform 4
openstack-glance
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 3 for RHEL 6 | openstack-glance-0:2013.1.4-1.el6ost | Fixed | RHSA-2013:1525 |
| Red Hat OpenStack Platform 4 | openstack-glance | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (14)
- http://rhn.redhat.com/errata/RHSA-2013-1525.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/10/15/8 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/10/16/9 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/63159 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2003-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2013-4428 Vendor Advisory
- https://bugs.launchpad.net/glance/+bug/1235226 x_refsource_CONFIRMExploitThird Party Advisory
- https://bugs.launchpad.net/glance/+bug/1235378 x_refsource_CONFIRMExploitThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1019572 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-4305 Advisory
- https://launchpad.net/glance/+milestone/2013.1.4 x_refsource_CONFIRMPatchThird Party Advisory
- https://launchpad.net/glance/+milestone/2013.2 x_refsource_CONFIRMPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-4428
- https://www.cve.org/CVERecord?id=CVE-2013-4428
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 27, 2013
Updated Aug 6, 2024
Reserved Jun 12, 2013
Link CVE-2013-4428
CISA Vulnrichment
No data
GitHub
No data