CVE-2014-1948
published 2014-02-14CVE-2014-1948: OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend…
PriorityP46low2.6CVSS 2.0
AVLACHAuNCPIPAN
EPSS
0.31%
23.7th percentile
OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glance | < glance 2013.2.2-1 (bookworm) | glance 2013.2.2-1 (bookworm) |
| glance_project | glance | >= 0 < 2013.2.2-1 | 2013.2.2-1 |
| glance_project | glance | >= 0 < 2013.2.2-1 | 2013.2.2-1 |
| glance_project | glance | >= 0 < 2013.2.2-1 | 2013.2.2-1 |
| glance_project | glance | >= 0 < 2013.2.2-1 | 2013.2.2-1 |
| glance_project | glance | >= 0 < 11.0.0a0 | 11.0.0a0 |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
CVSS provenance
nvdv2.02.6LOWAV:L/AC:H/Au:N/C:P/I:P/A:N
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Glance sensitive information disclosure via logs
ghsa·2022-05-17
CVE-2014-1948 [MEDIUM] CWE-532 OpenStack Glance sensitive information disclosure via logs
OpenStack Glance sensitive information disclosure via logs
OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.
OSV
OpenStack Glance sensitive information disclosure via logs
osv·2022-05-17
CVE-2014-1948 [MEDIUM] OpenStack Glance sensitive information disclosure via logs
OpenStack Glance sensitive information disclosure via logs
OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.
OSV
CVE-2014-1948: OpenStack Image Registry and Delivery Service (Glance) 2013
osv·2014-02-14·CVSS 2.6
CVE-2014-1948 [LOW] CVE-2014-1948: OpenStack Image Registry and Delivery Service (Glance) 2013
OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.
Red Hat
openstack-glance: Glance Swift store backend password leak
vendor_redhat·2014-02-12·CVSS 2.6
CVE-2014-1948 [LOW] CWE-532 openstack-glance: Glance Swift store backend password leak
openstack-glance: Glance Swift store backend password leak
OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.
Package: openstack-glance (Red Hat OpenStack Platform 3) - Not affected
Debian
CVE-2014-1948: glance - OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 a...
vendor_debian·2014·CVSS 2.6
CVE-2014-1948 [LOW] CVE-2014-1948: glance - OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 a...
OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.
Scope: local
bookworm: resolved (fixed in 2013.2.2-1)
bullseye: resolved (fixed in 2013.2.2-1)
forky: resolved (fixed in 2013.2.2-1)
sid: resolved (fixed in 2013.2.2-1)
trixie: resolved (fixed in 2013.2.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-1948 openstack-glance: Glance Swift store backend password leak [fedora-20]
bugzilla·2014-02-13·CVSS 2.6
CVE-2014-1948 [LOW] CVE-2014-1948 openstack-glance: Glance Swift store backend password leak [fedora-20]
CVE-2014-1948 openstack-glance: Glance Swift store backend password leak [fedora-20]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-20 tracking b
Bugzilla
CVE-2014-1948 openstack-glance: Glance Swift store backend password leak [fedora-19]
bugzilla·2014-02-13·CVSS 2.6
CVE-2014-1948 [LOW] CVE-2014-1948 openstack-glance: Glance Swift store backend password leak [fedora-19]
CVE-2014-1948 openstack-glance: Glance Swift store backend password leak [fedora-19]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-19 tracking b
Bugzilla
CVE-2014-1948 openstack-glance: Glance Swift store backend password leak
bugzilla·2014-02-12·CVSS 2.6
CVE-2014-1948 [LOW] CVE-2014-1948 openstack-glance: Glance Swift store backend password leak
CVE-2014-1948 openstack-glance: Glance Swift store backend password leak
A flaw was reported [1],[2] in OpenStack Glance 2013.2 versions up to and including 2013.2.1 and is described as follows:
Nikhil Komawar from Rackspace reported an information leak in Glance
logs. The password for the Swift store backend is logged at WARNING
level as part of the URL when authentication to a store fails if
image location is not disabled by policy or the store is a
single-tenant configuration. An attacker with access to the logs
(local shell, log aggregation system access, or accidental leak) may
leverage this vulnerability to elevate privileges and gain direct
full access to the Glance Swift store backend. Only Glance setups
using the Swift store backend are affected.
This has been corrected in up
http://rhn.redhat.com/errata/RHSA-2014-0229.htmlhttp://secunia.com/advisories/56419http://www.openwall.com/lists/oss-security/2014/02/12/18http://www.securityfocus.com/bid/65507https://bugs.launchpad.net/glance/+bug/1275062http://rhn.redhat.com/errata/RHSA-2014-0229.htmlhttp://secunia.com/advisories/56419http://www.openwall.com/lists/oss-security/2014/02/12/18http://www.securityfocus.com/bid/65507https://bugs.launchpad.net/glance/+bug/1275062
2014-02-14
Published