Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 461760 (CVE-2013-1840)

Summary: <app-admin/glance-2012.2.3-r1: Backend credentials leak in Glance v1 API (CVE-2013-1840)
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://bugzilla.redhat.com/show_bug.cgi?id=920393
Whiteboard: ~4 [noglsa]
Package list:
Runtime testing required: ---

Description Agostino Sarubbo gentoo-dev 2013-03-14 20:17:28 UTC
From ${URL} :

Thierry Carrez (thierry@openstack.org) reports:

Title: Backend credentials leak in Glance v1 API
Reporter: Stuart McLaren (HP)
Products: Glance
Affects: All versions

Description:
Stuart McLaren from HP reported a vulnerability in the information
potentially returned to the user in Glance v1 API. If an authenticated
user requests, through the v1 API, an image that is already cached, the
headers returned may disclose the Glance operator's backend credentials
for that endpoint. Only setups accepting the Glance v1 API and using
either the single-tenant Swift store or S3 store are affected.

Proposed patches:
See attached patches. Unless a flaw is discovered in them, these patches
will be merged to Glance master (Grizzly), stable/folsom, and
stable/essex branches on the public disclosure date.
Comment 2 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2013-03-14 21:07:53 UTC
fixed in =app-admin/glance-2012.2.3-r1

glance-2012.2.3 was removed
Comment 3 Sean Amoss (RETIRED) gentoo-dev Security 2013-03-14 21:53:49 UTC
Thanks, Matthew. 

Closing noglsa for ~arch only.