Information Exposure Affecting glance package, versions <2012.1.1-4
Snyk CVSS
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIAN11-GLANCE-527822
- published 24 Feb 2013
- disclosed 24 Feb 2013
Introduced: 24 Feb 2013
CVE-2013-0212 Open this link in a new tabHow to fix?
Upgrade Debian:11
glance
to version 2012.1.1-4 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream glance
package and not the glance
package as distributed by Debian:11
.
See How to fix?
for Debian:11
relevant fixed versions and status.
store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.
References
- ADVISORY
- GitHub Commit
- GitHub Commit
- GitHub Commit
- https://bugs.launchpad.net/glance/+bug/1098962
- https://launchpad.net/glance/+milestone/2012.2.3
- https://lists.launchpad.net/openstack/msg20517.html
- http://ubuntu.com/usn/usn-1710-1
- OSS security Advisory
- RedHat Bugzilla Bug
- RedHat Security Advisory
- Secunia Advisory
- Secunia Advisory
- Ubuntu CVE Tracker
- secalert@redhat.com
- secalert@redhat.com