USN-6630-1: Glance_store vulnerability
It was discovered that Glancestore incorrectly handled logging when the DEBUG log level is enabled. A local attacker could use this issue to obtain accesskey values.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6630-1?
The severity of USN-6630-1 is considered high due to the potential for local attackers to access sensitive access_key values.
How do I fix USN-6630-1?
To fix USN-6630-1, upgrade to the patched versions of python3-glance-store: 4.6.1-0ubuntu1.1 for Ubuntu 23.10, 3.0.0-0ubuntu1.4 for Ubuntu 22.04, or 2.0.0-0ubuntu4.3 for Ubuntu 20.04.
Who is affected by the USN-6630-1 vulnerability?
Users running specific versions of python3-glance-store on Ubuntu 23.10, 22.04, and 20.04 are affected by the USN-6630-1 vulnerability.
What is the cause of the USN-6630-1 vulnerability?
The USN-6630-1 vulnerability is caused by improper handling of logging in Glance_store when the DEBUG log level is enabled.
Can a remote attacker exploit USN-6630-1?
No, USN-6630-1 can only be exploited by a local attacker with access to the system.