Lucene search

K
githubGitHub Advisory DatabaseGHSA-C8W9-83VG-R8VV
HistoryMay 17, 2022 - 1:36 a.m.

OpenStack Glance is vulnerable to Exposure of Sensitive Information

2022-05-1701:36:25
CWE-200
GitHub Advisory Database
github.com
7
openstack
glance
v1 api
vulnerability
single-tenant
swift
s3
essex
folsom
grizzly
authenticated users
backend credentials
cached image

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0.003

Percentile

70.9%

The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator’s backend credentials via a request for a cached image.

Affected configurations

Vulners
Node
glance_projectglanceRange<11.0.0a0
VendorProductVersionCPE
glance_projectglance*cpe:2.3:a:glance_project:glance:*:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0.003

Percentile

70.9%