CVE Database
/

CVE-2013-1840

Back to search

CVE-2013-1840

Published: Mar 22, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-1764-1
vendor-advisory
x_refsource_UBUNTU
52565
third-party-advisory
x_refsource_SECUNIA
RHSA-2013:0707
vendor-advisory
x_refsource_REDHAT
91304
vdb-entry
x_refsource_OSVDB
58490
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now