Hide Forgot
Thierry Carrez from OpenStack reports: Title: Glance image_download policy not enforced for cached images Reporter: Stuart McLaren (HP) Products: Glance Affects: Folsom, Grizzly Description: Stuart McLaren from HP reported a vulnerability in Glance download_image policy enforcement in the case of cached images. Deployers may opt to set a download_image policy to restrict image download to specific roles. However, when an image is previously cached by an authorized download, any authenticated user could download image contents if it can determine the image UUID, bypassing any download_image policy restrictions. This could result in disclosure of image contents that were thought to be protected by the download_image policy setting. Only setups making use of the download_image policy are affected. External references: https://bugs.launchpad.net/glance/+bug/1235378
Acknowledgements: Red Hat would like to thank the OpenStack Project for reporting this issue. The OpenStack Project acknowledges Stuart McLaren from HP as the original reporter.
Created openstack-glance tracking bugs for this issue: Affects: fedora-all [bug 1019580] Affects: epel-6 [bug 1019581]
Created attachment 814782 [details] CVE-2013-4428.folsom.diff
Created attachment 814783 [details] CVE-2013-4428.grizzly.diff
This issue has been addressed in following products: OpenStack 3 for RHEL 6 Via RHSA-2013:1525 https://rhn.redhat.com/errata/RHSA-2013-1525.html