CVE-2013-4428
Glance: image_download policy not enforced for cached images
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly con versiones anteriores a 2013.1.4, y Havana con versiones anteriores a 2013.2, cuando se configura la política image_download, no restringe adecuadamente el acceso a las imágenes almacenadas en caché, lo que permite a usuarios remotos autenticados leer de otra manera imágenes restringidas a través de un imagen UUID.
The openstack-glance packages provide a service that acts as a registry for virtual machine images. A flaw was found in the Glance download_image policy enforcement for cached system images. When an image was previously cached by an authorized download, any authenticated user able to determine the image by its UUID could download that image, bypassing the download_image policy. Only setups making use of the download_image policy were affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-06-12 CVE Reserved
- 2013-10-23 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2013/10/15/8 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2013/10/16/9 | Mailing List |
|
http://www.securityfocus.com/bid/63159 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://bugs.launchpad.net/glance/+bug/1235226 | 2024-08-06 | |
https://bugs.launchpad.net/glance/+bug/1235378 | 2024-08-06 |
URL | Date | SRC |
---|---|---|
https://launchpad.net/glance/+milestone/2013.1.4 | 2018-11-15 | |
https://launchpad.net/glance/+milestone/2013.2 | 2018-11-15 |
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2013-1525.html | 2018-11-15 | |
http://www.ubuntu.com/usn/USN-2003-1 | 2018-11-15 | |
https://access.redhat.com/security/cve/CVE-2013-4428 | 2013-11-18 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1019572 | 2013-11-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openstack Search vendor "Openstack" | Glance Search vendor "Openstack" for product "Glance" | >= 2012.2 <= 2012.2.4 Search vendor "Openstack" for product "Glance" and version " >= 2012.2 <= 2012.2.4" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Glance Search vendor "Openstack" for product "Glance" | >= 2013.1 < 2013.1.4 Search vendor "Openstack" for product "Glance" and version " >= 2013.1 < 2013.1.4" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Glance Search vendor "Openstack" for product "Glance" | 2013.2 Search vendor "Openstack" for product "Glance" and version "2013.2" | milestone1 |
Affected
| ||||||
Openstack Search vendor "Openstack" | Glance Search vendor "Openstack" for product "Glance" | 2013.2 Search vendor "Openstack" for product "Glance" and version "2013.2" | milestone2 |
Affected
| ||||||
Openstack Search vendor "Openstack" | Glance Search vendor "Openstack" for product "Glance" | 2013.2 Search vendor "Openstack" for product "Glance" and version "2013.2" | milestone3 |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.10 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.10" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 13.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "13.04" | - |
Affected
|