Bug 902964 - (CVE-2013-0212) CVE-2013-0212 openstack-glance: Backend password leak in Glance error message
CVE-2013-0212 openstack-glance: Backend password leak in Glance error message
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
: Security
Depends On: 903032 903033
Blocks: 902968
  Show dependency treegraph
Reported: 2013-01-22 15:03 EST by Kurt Seifried
Modified: 2016-04-26 17:02 EDT (History)
8 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2013-08-09 00:31:55 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
essex-CVE-2013-0212.patch (3.00 KB, patch)
2013-01-22 15:05 EST, Kurt Seifried
no flags Details | Diff
folsom-CVE-2013-0212.patch (3.50 KB, patch)
2013-01-22 15:06 EST, Kurt Seifried
no flags Details | Diff
grizzly-CVE-2013-0212.patch (3.57 KB, patch)
2013-01-22 15:06 EST, Kurt Seifried
no flags Details | Diff

  None (edit)
Description Kurt Seifried 2013-01-22 15:03:03 EST
Thierry Carrez (thierry@openstack.org) reports on behalf of the OpenStack Project:

Title: Backend password leak in Glance error message
Reporter: Dan Prince (Red Hat)
Products: Glance
Affects: All versions

Dan Prince of Red Hat discovered an issue in Glance error reporting. By
creating an image in Glance by URL that references a mis-configured
Swift endpoint, or if the Swift endpoint that a previously-ACTIVE image
references for any reason becomes unusable, an authenticated user may
access the Glance operator's Swift credentials for that endpoint. Only
setups that use the single-tenant Swift store are affected.

Proposed patches:
See attached patches for current development tree (Grizzly) and the
Folsom and Essex series. Unless a flaw is discovered in them, these
proposed patches will be merged to Glance master, stable/folsom and
stable/essex branches on the public disclosure date.
Comment 1 Kurt Seifried 2013-01-22 15:05:56 EST
Created attachment 685412 [details]
Comment 2 Kurt Seifried 2013-01-22 15:06:13 EST
Created attachment 685413 [details]
Comment 3 Kurt Seifried 2013-01-22 15:06:31 EST
Created attachment 685414 [details]
Comment 7 Murray McAllister 2013-01-29 01:16:03 EST

This issue was discovered by Dan Prince of Red Hat.
Comment 8 Kurt Seifried 2013-01-29 13:24:42 EST
This is now public: https://bugs.launchpad.net/glance/+bug/1098962
Comment 9 errata-xmlrpc 2013-01-30 16:06:05 EST
This issue has been addressed in following products:

  OpenStack Folsom for RHEL 6

Via RHSA-2013:0209 https://rhn.redhat.com/errata/RHSA-2013-0209.html
Comment 10 Fedora Update System 2013-02-13 21:30:55 EST
openstack-glance-2012.2.3-1.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.