CVE-2013-4428
Glance: image_download policy not enforced for cached images
Severity Score
3.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly con versiones anteriores a 2013.1.4, y Havana con versiones anteriores a 2013.2, cuando se configura la política image_download, no restringe adecuadamente el acceso a las imágenes almacenadas en caché, lo que permite a usuarios remotos autenticados leer de otra manera imágenes restringidas a través de un imagen UUID.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2013-06-12 CVE Reserved
- 2013-10-23 CVE Published
- 2023-06-08 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2013/10/15/8 | Mailing List | |
http://www.openwall.com/lists/oss-security/2013/10/16/9 | Mailing List | |
http://www.securityfocus.com/bid/63159 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://bugs.launchpad.net/glance/+bug/1235226 | 2024-08-06 | |
https://bugs.launchpad.net/glance/+bug/1235378 | 2024-08-06 |
URL | Date | SRC |
---|---|---|
https://launchpad.net/glance/+milestone/2013.1.4 | 2018-11-15 | |
https://launchpad.net/glance/+milestone/2013.2 | 2018-11-15 |
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2013-1525.html | 2018-11-15 | |
http://www.ubuntu.com/usn/USN-2003-1 | 2018-11-15 | |
https://access.redhat.com/security/cve/CVE-2013-4428 | 2013-11-18 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1019572 | 2013-11-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openstack Search vendor "Openstack" | Glance Search vendor "Openstack" for product "Glance" | >= 2012.2 <= 2012.2.4 Search vendor "Openstack" for product "Glance" and version " >= 2012.2 <= 2012.2.4" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Glance Search vendor "Openstack" for product "Glance" | >= 2013.1 < 2013.1.4 Search vendor "Openstack" for product "Glance" and version " >= 2013.1 < 2013.1.4" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Glance Search vendor "Openstack" for product "Glance" | 2013.2 Search vendor "Openstack" for product "Glance" and version "2013.2" | milestone1 |
Affected
| ||||||
Openstack Search vendor "Openstack" | Glance Search vendor "Openstack" for product "Glance" | 2013.2 Search vendor "Openstack" for product "Glance" and version "2013.2" | milestone2 |
Affected
| ||||||
Openstack Search vendor "Openstack" | Glance Search vendor "Openstack" for product "Glance" | 2013.2 Search vendor "Openstack" for product "Glance" and version "2013.2" | milestone3 |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.10 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.10" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 13.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "13.04" | - |
Affected
|