OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
2013-10-27T00:55:03.963
2025-04-11T00:51:21.963
Deferred
CVSSv2: 3.5 (LOW)
AV:N/AC:M/Au:S/C:P/I:N/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openstack | glance | ≤ 2012.2.4 | Yes |
Application | openstack | glance | < 2013.1.4 | Yes |
Application | openstack | glance | 2013.2 | Yes |
Application | openstack | glance | 2013.2 | Yes |
Application | openstack | glance | 2013.2 | Yes |
Operating System | canonical | ubuntu_linux | 12.10 | Yes |
Operating System | canonical | ubuntu_linux | 13.04 | Yes |