The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.
2013-03-22T21:55:01.487
2025-04-11T00:51:21.963
Deferred
CVSSv2: 3.5 (LOW)
AV:N/AC:M/Au:S/C:P/I:N/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openstack | glance | v1 | Yes |
Application | openstack | essex | 2012.1 | No |
Application | openstack | folsom | 2012.2 | No |
Application | amazon | s3_store | - | No |
Application | openstack | swift | - | No |