CVE-2013-4428

EUVD-2013-4305
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.5 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
Affected Products (NVD)
VendorProductVersion
openstackglance
2012.2 ≤
𝑥
≤ 2012.2.4
openstackglance
2013.1 ≤
𝑥
< 2013.1.4
openstackglance
2013.2:milestone1
openstackglance
2013.2:milestone2
openstackglance
2013.2:milestone3
canonicalubuntu_linux
12.10
canonicalubuntu_linux
13.04
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
glance
bookworm
2:25.1.0-2+deb12u1
fixed
bookworm (security)
2:25.1.0-2+deb12u1
fixed
bullseye
2:21.0.0-2+deb11u1
fixed
bullseye (security)
2:21.1.0-1+deb11u2
fixed
sid
2:29.0.0-1
fixed
trixie
2:29.0.0-1
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
glance
lucid
dne
precise
not-affected
quantal
Fixed 2012.2.4-0ubuntu1.1
released
raring
Fixed 1:2013.1.3-0ubuntu1.1
released
saucy
not-affected
Common Weakness Enumeration