CVE-2013-1840
published 2013-03-22CVE-2013-1840: The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which…
PriorityP414low3.5CVSS 2.0
AVNACMAuSCPINAN
EPSS
1.36%
68.4th percentile
The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glance | < glance 2012.1.1-5 (bookworm) | glance 2012.1.1-5 (bookworm) |
| glance_project | glance | >= 0 < 2012.1.1-5 | 2012.1.1-5 |
| glance_project | glance | >= 0 < 2012.1.1-5 | 2012.1.1-5 |
| glance_project | glance | >= 0 < 2012.1.1-5 | 2012.1.1-5 |
| glance_project | glance | >= 0 < 2012.1.1-5 | 2012.1.1-5 |
| glance_project | glance | >= 0 < 11.0.0a0 | 11.0.0a0 |
| openstack | glance | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
osv3.5LOW
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
CVE-2013-1840: The v1 API in OpenStack Glance Essex (2012
vendor_redhat·2013-03-22·CVSS 3.5
CVE-2013-1840 [LOW] CWE-201 CVE-2013-1840: The v1 API in OpenStack Glance Essex (2012
The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.
A flaw was found in OpenStack Glance. Remote authenticated users can exploit this vulnerability by requesting a cached image when the single-tenant Swift or S3 store is in use. This action causes the system to report the location field, which can lead to the disclosure of the operator's backend credentials.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread ins
Ubuntu
OpenStack Glance vulnerability
vendor_ubuntu·2013-03-14
CVE-2013-1840 OpenStack Glance vulnerability
Title: OpenStack Glance vulnerability
Summary: Glance could be made to expose sensitive information over the network.
Stuart McLaren discovered an issue with Glance v1 API requests. An
authenticated attacker could exploit this to expose the Glance operator's
Swift and/or S3 credentials via the response headers when requesting a
cached image.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2013-1840: glance - The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, whe...
vendor_debian·2013·CVSS 3.5
CVE-2013-1840 [LOW] CVE-2013-1840: glance - The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, whe...
The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.
Scope: local
bookworm: resolved (fixed in 2012.1.1-5)
bullseye: resolved (fixed in 2012.1.1-5)
forky: resolved (fixed in 2012.1.1-5)
sid: resolved (fixed in 2012.1.1-5)
trixie: resolved (fixed in 2012.1.1-5)
OSV
OpenStack Glance is vulnerable to Exposure of Sensitive Information
osv·2022-05-17
CVE-2013-1840 [LOW] OpenStack Glance is vulnerable to Exposure of Sensitive Information
OpenStack Glance is vulnerable to Exposure of Sensitive Information
The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.
GHSA
OpenStack Glance is vulnerable to Exposure of Sensitive Information
ghsa·2022-05-17
CVE-2013-1840 [LOW] CWE-200 OpenStack Glance is vulnerable to Exposure of Sensitive Information
OpenStack Glance is vulnerable to Exposure of Sensitive Information
The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.
OSV
CVE-2013-1840: The v1 API in OpenStack Glance Essex (2012
osv·2013-03-22·CVSS 3.5
CVE-2013-1840 [LOW] CVE-2013-1840: The v1 API in OpenStack Glance Essex (2012
The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.
No detection rules found.
No public exploits indexed.
http://osvdb.org/91304http://rhn.redhat.com/errata/RHSA-2013-0707.htmlhttp://secunia.com/advisories/52565http://www.openwall.com/lists/oss-security/2013/03/14/15http://www.securityfocus.com/bid/58490http://www.ubuntu.com/usn/USN-1764-1https://bugs.launchpad.net/glance/+bug/1135541https://exchange.xforce.ibmcloud.com/vulnerabilities/82878https://review.openstack.org/#/c/24437/https://review.openstack.org/#/c/24438/https://review.openstack.org/#/c/24439/http://osvdb.org/91304http://rhn.redhat.com/errata/RHSA-2013-0707.htmlhttp://secunia.com/advisories/52565http://www.openwall.com/lists/oss-security/2013/03/14/15http://www.securityfocus.com/bid/58490http://www.ubuntu.com/usn/USN-1764-1https://bugs.launchpad.net/glance/+bug/1135541https://exchange.xforce.ibmcloud.com/vulnerabilities/82878https://review.openstack.org/#/c/24437/https://review.openstack.org/#/c/24438/https://review.openstack.org/#/c/24439/
2013-03-22
Published