First published: Mon Jul 29 2013(Updated: )
Thierry Carrez (thierry) reports: A vulnerability was fixed publicly in OpenStack Python Glance client recently, and we think it warrants a security advisory to make sure everyone is aware of it. We obviously can't embargo anything here since the issue is public already, but we figured you would still appreciate a day heads-up before we publish the advisory and attract the rest of the world attention on the issue. Title: Missing SSL certificate check in Python glance client Reporter: Thomas Leaman (HP) Products: python-glanceclient Affects: All versions Description: Thomas Leaman from HP reported that the Python Glance client was failing to properly check certificates during the establishment of HTTPS connections. A remote attacker with access over segments of the network between client and server could potentially set up a man-in the-middle attack and access the contents of the Glance client request (or response). python-glanceclient fix (will be included in future release): <a href="https://review.openstack.org/#/c/33464/">https://review.openstack.org/#/c/33464/</a> References: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4111">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4111</a> <a href="https://bugs.launchpad.net/python-glanceclient/+bug/1192229">https://bugs.launchpad.net/python-glanceclient/+bug/1192229</a>
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Python glanceclient | <= |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-989738 is classified as a security vulnerability in the OpenStack Python Glance client.
To fix REDHAT-BUG-989738, update to the latest version of the OpenStack Python Glance client that includes the security patches.
Not addressing REDHAT-BUG-989738 could lead to unauthorized access or exposure of sensitive information within OpenStack deployments.
All versions of the OpenStack Python Glance client prior to the security patch are affected by REDHAT-BUG-989738.
More information about REDHAT-BUG-989738 can be found in the official bug report and the OpenStack security advisory.