CVE-2013-4428
27.10.2013, 00:55
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.Enginsight
| Vendor | Product | Version |
|---|---|---|
| openstack | glance | 2012.2 ≤ 𝑥 ≤ 2012.2.4 |
| openstack | glance | 2013.1 ≤ 𝑥 < 2013.1.4 |
| openstack | glance | 2013.2:milestone1 |
| openstack | glance | 2013.2:milestone2 |
| openstack | glance | 2013.2:milestone3 |
| canonical | ubuntu_linux | 12.10 |
| canonical | ubuntu_linux | 13.04 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References