First published: Sun Oct 27 2013(Updated: )
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Glance | >=2012.2<=2012.2.4 | |
OpenStack Glance | >=2013.1<2013.1.4 | |
OpenStack Glance | =2013.2-milestone1 | |
OpenStack Glance | =2013.2-milestone2 | |
OpenStack Glance | =2013.2-milestone3 | |
Canonical Ubuntu Linux | =12.10 | |
Canonical Ubuntu Linux | =13.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.