CVE-2013-4428
published 2013-10-27CVE-2013-4428: OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured…
PriorityP421low3.5CVSS 2.0
AVNACMAuSCPINAN
EPSS
3.08%
86.1th percentile
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | glance | < glance 2013.2-1 (bookworm) | glance 2013.2-1 (bookworm) |
| glance_project | glance | >= 0 < 2013.2-1 | 2013.2-1 |
| glance_project | glance | >= 0 < 2013.2-1 | 2013.2-1 |
| glance_project | glance | >= 0 < 2013.2-1 | 2013.2-1 |
| glance_project | glance | >= 0 < 2013.2-1 | 2013.2-1 |
| openstack | glance | — | — |
| openstack | glance | 2012.2 – 2012.2.4 | — |
| openstack | glance | >= 2013.1 < 2013.1.4 | 2013.1.4 |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
osv3.5LOW
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Glance vulnerability
vendor_ubuntu·2013-10-23
CVE-2013-4428 Glance vulnerability
Title: Glance vulnerability
Summary: Glance could be made to expose sensitive information over the network
under certain circumstances.
Stuart McLaren discovered that Glance did not properly enforce the
'download_image' policy for cached images. An authenticated user could
exploit this to obtain sensitive information in an image protected by this
setting.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Glance: image_download policy not enforced for cached images
vendor_redhat·2013-10-04·CVSS 3.5
CVE-2013-4428 [LOW] Glance: image_download policy not enforced for cached images
Glance: image_download policy not enforced for cached images
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
Package: openstack-glance (Red Hat OpenStack Platform 4) - Affected
Debian
CVE-2013-4428: glance - OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 20...
vendor_debian·2013·CVSS 3.5
CVE-2013-4428 [LOW] CVE-2013-4428: glance - OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 20...
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
Scope: local
bookworm: resolved (fixed in 2013.2-1)
bullseye: resolved (fixed in 2013.2-1)
forky: resolved (fixed in 2013.2-1)
sid: resolved (fixed in 2013.2-1)
trixie: resolved (fixed in 2013.2-1)
GHSA
GHSA-hv7x-f537-wh3x: OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013
ghsa_unreviewed·2022-05-14
CVE-2013-4428 [LOW] GHSA-hv7x-f537-wh3x: OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
OSV
CVE-2013-4428: OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013
osv·2013-10-27·CVSS 3.5
CVE-2013-4428 [LOW] CVE-2013-4428: OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4428 openstack-glance: OpenStack Glance: image_download policy not enforced for cached images [fedora-all]
bugzilla·2013-10-16·CVSS 3.5
CVE-2013-4428 [LOW] CVE-2013-4428 openstack-glance: OpenStack Glance: image_download policy not enforced for cached images [fedora-all]
CVE-2013-4428 openstack-glance: OpenStack Glance: image_download policy not enforced for cached images [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when a
Bugzilla
CVE-2013-4428 openstack-glance: OpenStack Glance: image_download policy not enforced for cached images [epel-6]
bugzilla·2013-10-16·CVSS 3.5
CVE-2013-4428 [LOW] CVE-2013-4428 openstack-glance: OpenStack Glance: image_download policy not enforced for cached images [epel-6]
CVE-2013-4428 openstack-glance: OpenStack Glance: image_download policy not enforced for cached images [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when
Bugzilla
CVE-2013-4428 OpenStack Glance: image_download policy not enforced for cached images
bugzilla·2013-10-16·CVSS 3.5
CVE-2013-4428 [LOW] CVE-2013-4428 OpenStack Glance: image_download policy not enforced for cached images
CVE-2013-4428 OpenStack Glance: image_download policy not enforced for cached images
Thierry Carrez from OpenStack reports:
Title: Glance image_download policy not enforced for cached images
Reporter: Stuart McLaren (HP)
Products: Glance
Affects: Folsom, Grizzly
Description:
Stuart McLaren from HP reported a vulnerability in Glance download_image
policy enforcement in the case of cached images. Deployers may opt to
set a download_image policy to restrict image download to specific
roles. However, when an image is previously cached by an authorized
download, any authenticated user could download image contents if it can
determine the image UUID, bypassing any download_image policy
restrictions. This could result in disclosure of image contents that
were thought to be protected by the dow
http://rhn.redhat.com/errata/RHSA-2013-1525.htmlhttp://www.openwall.com/lists/oss-security/2013/10/15/8http://www.openwall.com/lists/oss-security/2013/10/16/9http://www.securityfocus.com/bid/63159http://www.ubuntu.com/usn/USN-2003-1https://bugs.launchpad.net/glance/+bug/1235226https://bugs.launchpad.net/glance/+bug/1235378https://launchpad.net/glance/+milestone/2013.1.4https://launchpad.net/glance/+milestone/2013.2http://rhn.redhat.com/errata/RHSA-2013-1525.htmlhttp://www.openwall.com/lists/oss-security/2013/10/15/8http://www.openwall.com/lists/oss-security/2013/10/16/9http://www.securityfocus.com/bid/63159http://www.ubuntu.com/usn/USN-2003-1https://bugs.launchpad.net/glance/+bug/1235226https://bugs.launchpad.net/glance/+bug/1235378https://launchpad.net/glance/+milestone/2013.1.4https://launchpad.net/glance/+milestone/2013.2
2013-10-27
Published