First published: Tue Jan 22 2013(Updated: )
Thierry Carrez (thierry) reports on behalf of the OpenStack Project: Title: Backend password leak in Glance error message Reporter: Dan Prince (Red Hat) Products: Glance Affects: All versions Dan Prince of Red Hat discovered an issue in Glance error reporting. By creating an image in Glance by URL that references a mis-configured Swift endpoint, or if the Swift endpoint that a previously-ACTIVE image references for any reason becomes unusable, an authenticated user may access the Glance operator's Swift credentials for that endpoint. Only setups that use the single-tenant Swift store are affected. Proposed patches: See attached patches for current development tree (Grizzly) and the Folsom and Essex series. Unless a flaw is discovered in them, these proposed patches will be merged to Glance master, stable/folsom and stable/essex branches on the public disclosure date.
Affected Software | Affected Version | How to fix |
---|---|---|
Glance | <=9999 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The REDHAT-BUG-902964 vulnerability is considered critical due to the potential exposure of backend passwords in error messages.
To mitigate REDHAT-BUG-902964, update to the latest version of OpenStack Glance that addresses the password leak issue.
All versions of OpenStack Glance are affected by REDHAT-BUG-902964.
REDHAT-BUG-902964 impacts the error reporting mechanism within OpenStack Glance.
REDHAT-BUG-902964 was reported by Dan Prince of Red Hat on behalf of the OpenStack Project.