CVE-2013-0212
Summary
| CVE | CVE-2013-0212 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-02-24 21:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 11.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 12.04 | - | lts | All |
| Operating System | Canonical | Ubuntu Linux | 12.10 | All | All | All |
| Application | Openstack | Image Registry And Delivery Service Glance | 2012.1 | All | All | All |
| Application | Openstack | Image Registry And Delivery Service Glance | 2012.2 | All | All | All |
| Application | Openstack | Image Registry And Delivery Service Glance | 2012.2.1 | All | All | All |
| Application | Openstack | Image Registry And Delivery Service Glance | 2012.2.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Remove Swift location/password from messages. · openstack/glance@37d4d96 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| 2012.2.3 : Glance | af854a3a-2127-422b-91ae-364da2661108 | launchpad.net | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| Remove Swift location/password from messages. · openstack/glance@e962731 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| Remove Swift location/password from messages. · openstack/glance@96a470b · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| 902964 – (CVE-2013-0212) CVE-2013-0212 openstack-glance: Backend password leak in Glance error message | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch |
| USN-1710-1: OpenStack Glance vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | Patch |
| Bug #1098962 “[OSSA 2013-002] glance image-download can display ...” : Bugs : Glance | af854a3a-2127-422b-91ae-364da2661108 | bugs.launchpad.net | |
| Security Advisory SA51990 - Ubuntu update for glance - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| oss-security - [OSSA 2013-002] Backend password leak in Glance error message (CVE-2013-0212) | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Security Advisory SA51957 - OpenStack Glance Swift Backend Password Disclosure Security Issue - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [OSSA 2013-002] Backend password leak in Glance error message (CVE-2013-0212) : Mailing list archive : openstack team in Launchpad | af854a3a-2127-422b-91ae-364da2661108 | lists.launchpad.net | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| access.redhat.com | CVE-2013-0212 | MITRE | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.