CVE Database


Impact: Important
Public: 2013-01-29
CWE: CWE-209
Bugzilla: 902964: CVE-2013-0212 openstack-glance: Backend password leak in Glance error message


The MITRE CVE dictionary describes this issue as:

store/ in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.

Find out more about CVE-2013-0212 from the MITRE CVE dictionary and NIST NVD.

CVSS v2 metrics

Base Score: 4.0
Base Metrics: AV:N/AC:L/Au:S/C:P/I:N/A:N
Access Vector: Network
Access Complexity: Low
Authentication: Single Instance
Confidentiality Impact: Partial
Integrity Impact: None
Availability Impact: None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat security errata

Platform Errata Release Date
OpenStack Folsom (openstack-glance) RHSA-2013:0209 January 30, 2013

External References


This issue was discovered by Dan Prince of Red Hat.

This page is generated automatically and has not been checked for errors or omissions.

For clarification or corrections please contact the Red Hat Security Response Team.