CVE-2013-0212
published 2013-02-24CVE-2013-0212: store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's…
PriorityP417medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
2.96%
85.6th percentile
store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | glance | < glance 2012.1.1-4 (bookworm) | glance 2012.1.1-4 (bookworm) |
| glance_project | glance | >= 0 < 2012.1.1-4 | 2012.1.1-4 |
| glance_project | glance | >= 0 < 2012.1.1-4 | 2012.1.1-4 |
| glance_project | glance | >= 0 < 2012.1.1-4 | 2012.1.1-4 |
| glance_project | glance | >= 0 < 2012.1.1-4 | 2012.1.1-4 |
| glance_project | glance | >= 2012.1 < 2012.2.3 | 2012.2.3 |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Glance logs user name and password in cleartext
ghsa·2022-05-05
CVE-2013-0212 [MEDIUM] CWE-200 OpenStack Glance logs user name and password in cleartext
OpenStack Glance logs user name and password in cleartext
store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.
OSV
OpenStack Glance logs user name and password in cleartext
osv·2022-05-05
CVE-2013-0212 [MEDIUM] OpenStack Glance logs user name and password in cleartext
OpenStack Glance logs user name and password in cleartext
store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.
OSV
CVE-2013-0212: store/swift
osv·2013-02-24·CVSS 4.0
CVE-2013-0212 [MEDIUM] CVE-2013-0212: store/swift
store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.
Ubuntu
OpenStack Glance vulnerability
vendor_ubuntu·2013-01-29
CVE-2013-0212 OpenStack Glance vulnerability
Title: OpenStack Glance vulnerability
Summary: Glance could be made to expose sensitive information over the network.
Dan Prince discovered an issue in Glance error reporting. An authenticated
attacker could exploit this to expose the Glance operator's Swift
credentials for a misconfigured or otherwise unusable Swift endpoint.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-glance: Backend password leak in Glance error message
vendor_redhat·2013-01-29·CVSS 4.0
CVE-2013-0212 [MEDIUM] CWE-209 openstack-glance: Backend password leak in Glance error message
openstack-glance: Backend password leak in Glance error message
store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.
Debian
CVE-2013-0212: glance - store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2...
vendor_debian·2013·CVSS 4.0
CVE-2013-0212 [MEDIUM] CVE-2013-0212: glance - store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2...
store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.
Scope: local
bookworm: resolved (fixed in 2012.1.1-4)
bullseye: resolved (fixed in 2012.1.1-4)
forky: resolved (fixed in 2012.1.1-4)
sid: resolved (fixed in 2012.1.1-4)
trixie: resolved (fixed in 2012.1.1-4)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2013-0209.htmlhttp://secunia.com/advisories/51957http://secunia.com/advisories/51990http://ubuntu.com/usn/usn-1710-1http://www.openwall.com/lists/oss-security/2013/01/29/10https://bugs.launchpad.net/glance/+bug/1098962https://bugzilla.redhat.com/show_bug.cgi?id=902964https://github.com/openstack/glance/commit/37d4d96bf88c2bf3e7e9511b5e321cf4bed364b7https://github.com/openstack/glance/commit/96a470be64adcef97f235ca96ed3c59ed954a4c1https://github.com/openstack/glance/commit/e96273112b5b5da58d970796b7cfce04c5030a89https://launchpad.net/glance/+milestone/2012.2.3https://lists.launchpad.net/openstack/msg20517.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0209.htmlhttp://secunia.com/advisories/51957http://secunia.com/advisories/51990http://ubuntu.com/usn/usn-1710-1http://www.openwall.com/lists/oss-security/2013/01/29/10https://bugs.launchpad.net/glance/+bug/1098962https://bugzilla.redhat.com/show_bug.cgi?id=902964https://github.com/openstack/glance/commit/37d4d96bf88c2bf3e7e9511b5e321cf4bed364b7https://github.com/openstack/glance/commit/96a470be64adcef97f235ca96ed3c59ed954a4c1https://github.com/openstack/glance/commit/e96273112b5b5da58d970796b7cfce04c5030a89https://launchpad.net/glance/+milestone/2012.2.3https://lists.launchpad.net/openstack/msg20517.html
2013-02-24
Published