ossa/OSSA-2013-007.yaml

55 lines
1.4 KiB
YAML

advisory-date: 2013-03-14
advisory-id: OSSA-2013-007
advisory-title: 'Backend credentials leak in Glance v1 API'
advisory-description: 'Stuart McLaren from HP reported a vulnerability in the information
potentially returned to the user in Glance v1 API. If an authenticated user requests,
through the v1 API, an image that is already cached, the headers returned may disclose
the Glance operator''s backend credentials for that endpoint. Only setups accepting
the Glance v1 API and using either the single-tenant Swift store or S3 store are
affected.'
advisory-reference: http://lists.openstack.org/pipermail/openstack-announce/2013-March/000085.html
affected-products:
- product: glance
version: TODO
vulnerabilities:
- cve-id: CVE-2013-1840
impact-assessment:
source: 'Red Hat Product Security'
rating: moderate
assessment:
type: CVSS2
score: 3.5
detail: AV:N/AC:M/Au:S/C:P/I:N/A:N
classification:
source: 'Red Hat Product Security'
type: CWE
detail: TODO
reporters:
- name: 'Stuart McLaren'
affiliation: HP
reported:
- CVE-2013-1840
notes:
issues:
issue-tracking-system-url: https://launchpad.net/bugs/{id}
issue-tracking-system-type : 'launchpad'
issue-id:
- 1135541
reviews:
review-system-url: https://review.openstack.org/#/c/{id}
review-system-type: 'gerrit'
review-id:
- 24437
- 24438
- 24439