Summary: | <app-admin/glance-2013.1.4: image_download policy not enforced for cached images (CVE-2013-4428) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Mikle Kolyada <zlogene> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | trivial | ||
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://seclists.org/oss-sec/2013/q4/100 | ||
Whiteboard: | ~4 [noglsa] | ||
Package list: | Runtime testing required: | --- |
Description
Mikle Kolyada
![]() ![]() ![]() ![]() grizzly fixed, but the next folsom release should be out soon. CVE-2013-4428 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4428): OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the image_download policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID. folsom removed from tree, should be good to close now. |