REDHAT-BUG-902964: High severity openstack glance store vulnerability
Thierry Carrez (thierry) reports on behalf of the OpenStack Project:
Title: Backend password leak in Glance error message Reporter: Dan Prince (Red Hat) Products: Glance Affects: All versions
Dan Prince of Red Hat discovered an issue in Glance error reporting. By creating an image in Glance by URL that references a mis-configured Swift endpoint, or if the Swift endpoint that a previously-ACTIVE image references for any reason becomes unusable, an authenticated user may access the Glance operator's Swift credentials for that endpoint. Only setups that use the single-tenant Swift store are affected.
Proposed patches: See attached patches for current development tree (Grizzly) and the Folsom and Essex series. Unless a flaw is discovered in them, these proposed patches will be merged to Glance master, stable/folsom and stable/essex branches on the public disclosure date.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-902964?
The REDHAT-BUG-902964 vulnerability is considered critical due to the potential exposure of backend passwords in error messages.
How do I fix REDHAT-BUG-902964?
To mitigate REDHAT-BUG-902964, update to the latest version of OpenStack Glance that addresses the password leak issue.
What versions are affected by REDHAT-BUG-902964?
All versions of OpenStack Glance are affected by REDHAT-BUG-902964.
What does REDHAT-BUG-902964 impact?
REDHAT-BUG-902964 impacts the error reporting mechanism within OpenStack Glance.
Who reported REDHAT-BUG-902964?
REDHAT-BUG-902964 was reported by Dan Prince of Red Hat on behalf of the OpenStack Project.