OSSA-2013-002: Backend password leak in Glance error message

Date:

January 29, 2013

CVE:

CVE-2013-0212

Affects

  • Glance: All versions

Description

Dan Prince of Red Hat discovered an issue in Glance error reporting. By creating an image in Glance by URL that references a mis-configured Swift endpoint, or if the Swift endpoint that a previously-ACTIVE image references for any reason becomes unusable, an authenticated user may access the Glance operator’s Swift credentials for that endpoint. Only setups that use the single-tenant Swift store are affected.

Patches

Credits

  • Dan Prince from Red Hat (CVE-2013-0212)

References