store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 01:47
Type | Values Removed | Values Added |
---|---|---|
References | () http://rhn.redhat.com/errata/RHSA-2013-0209.html - Vendor Advisory | |
References | () http://secunia.com/advisories/51957 - Vendor Advisory | |
References | () http://secunia.com/advisories/51990 - Vendor Advisory | |
References | () http://ubuntu.com/usn/usn-1710-1 - Patch | |
References | () http://www.openwall.com/lists/oss-security/2013/01/29/10 - | |
References | () https://bugs.launchpad.net/glance/+bug/1098962 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=902964 - Patch | |
References | () https://github.com/openstack/glance/commit/37d4d96bf88c2bf3e7e9511b5e321cf4bed364b7 - | |
References | () https://github.com/openstack/glance/commit/96a470be64adcef97f235ca96ed3c59ed954a4c1 - | |
References | () https://github.com/openstack/glance/commit/e96273112b5b5da58d970796b7cfce04c5030a89 - | |
References | () https://launchpad.net/glance/+milestone/2012.2.3 - | |
References | () https://lists.launchpad.net/openstack/msg20517.html - |
Information
Published : 2013-02-24 21:55
Updated : 2024-11-21 01:47
NVD link : CVE-2013-0212
Mitre link : CVE-2013-0212
CVE.ORG link : CVE-2013-0212
JSON object : View
Products Affected
canonical
- ubuntu_linux
openstack
- image_registry_and_delivery_service_\(glance\)
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor