Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-1840
HistoryMar 14, 2013 - 12:00 a.m.

CVE-2013-1840

2013-03-1400:00:00
ubuntu.com
ubuntu.com
6

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

0.003 Low

EPSS

Percentile

70.9%

The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and
Grizzly, when using the single-tenant Swift or S3 store, reports the
location field, which allows remote authenticated users to obtain the
operator’s backend credentials via a request for a cached image.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchglance< 2012.1.3+stable~20120821-120fcf-0ubuntu1.5UNKNOWN
ubuntu12.10noarchglance< 2012.2.1-0ubuntu1.2UNKNOWN

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

0.003 Low

EPSS

Percentile

70.9%