Advisory Published
Updated

REDHAT-BUG-989738

First published: Mon Jul 29 2013(Updated: )

Thierry Carrez (thierry) reports: A vulnerability was fixed publicly in OpenStack Python Glance client recently, and we think it warrants a security advisory to make sure everyone is aware of it. We obviously can't embargo anything here since the issue is public already, but we figured you would still appreciate a day heads-up before we publish the advisory and attract the rest of the world attention on the issue. Title: Missing SSL certificate check in Python glance client Reporter: Thomas Leaman (HP) Products: python-glanceclient Affects: All versions Description: Thomas Leaman from HP reported that the Python Glance client was failing to properly check certificates during the establishment of HTTPS connections. A remote attacker with access over segments of the network between client and server could potentially set up a man-in the-middle attack and access the contents of the Glance client request (or response). python-glanceclient fix (will be included in future release): <a href="https://review.openstack.org/#/c/33464/">https://review.openstack.org/#/c/33464/</a> References: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4111">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4111</a> <a href="https://bugs.launchpad.net/python-glanceclient/+bug/1192229">https://bugs.launchpad.net/python-glanceclient/+bug/1192229</a>

Affected SoftwareAffected VersionHow to fix
OpenStack Python glanceclient<=

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of REDHAT-BUG-989738?

    The severity of REDHAT-BUG-989738 is classified as a security vulnerability in the OpenStack Python Glance client.

  • How do I fix REDHAT-BUG-989738?

    To fix REDHAT-BUG-989738, update to the latest version of the OpenStack Python Glance client that includes the security patches.

  • What are the implications of not addressing REDHAT-BUG-989738?

    Not addressing REDHAT-BUG-989738 could lead to unauthorized access or exposure of sensitive information within OpenStack deployments.

  • Which versions of OpenStack are affected by REDHAT-BUG-989738?

    All versions of the OpenStack Python Glance client prior to the security patch are affected by REDHAT-BUG-989738.

  • Where can I find more information about REDHAT-BUG-989738?

    More information about REDHAT-BUG-989738 can be found in the official bug report and the OpenStack security advisory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203