{"api_version":"1","generated_at":"2026-07-23T12:08:08+00:00","cve":"CVE-2013-0212","urls":{"html":"https://cve.report/CVE-2013-0212","api":"https://cve.report/api/cve/CVE-2013-0212.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-0212","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-0212"},"summary":{"title":"CVE-2013-0212","description":"store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.","state":"PUBLISHED","assigner":"redhat","published_at":"2013-02-24 21:55:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://github.com/openstack/glance/commit/37d4d96bf88c2bf3e7e9511b5e321cf4bed364b7","name":"https://github.com/openstack/glance/commit/37d4d96bf88c2bf3e7e9511b5e321cf4bed364b7","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Remove Swift location/password from messages. · openstack/glance@37d4d96 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://launchpad.net/glance/+milestone/2012.2.3","name":"https://launchpad.net/glance/+milestone/2012.2.3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"2012.2.3 : Glance","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2013-0209.html","name":"http://rhn.redhat.com/errata/RHSA-2013-0209.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://github.com/openstack/glance/commit/e96273112b5b5da58d970796b7cfce04c5030a89","name":"https://github.com/openstack/glance/commit/e96273112b5b5da58d970796b7cfce04c5030a89","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Remove Swift location/password from messages. · openstack/glance@e962731 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/openstack/glance/commit/96a470be64adcef97f235ca96ed3c59ed954a4c1","name":"https://github.com/openstack/glance/commit/96a470be64adcef97f235ca96ed3c59ed954a4c1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Remove Swift location/password from messages. · openstack/glance@96a470b · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=902964","name":"https://bugzilla.redhat.com/show_bug.cgi?id=902964","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"902964 – (CVE-2013-0212) CVE-2013-0212 openstack-glance: Backend password leak in Glance error message","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://ubuntu.com/usn/usn-1710-1","name":"http://ubuntu.com/usn/usn-1710-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"USN-1710-1: OpenStack Glance vulnerability | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.launchpad.net/glance/+bug/1098962","name":"https://bugs.launchpad.net/glance/+bug/1098962","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug #1098962 “[OSSA 2013-002] glance image-download can display ...” : Bugs : Glance","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/51990","name":"http://secunia.com/advisories/51990","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA51990 - Ubuntu update for glance - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2013/01/29/10","name":"http://www.openwall.com/lists/oss-security/2013/01/29/10","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - [OSSA 2013-002] Backend password leak in Glance error message (CVE-2013-0212)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/51957","name":"http://secunia.com/advisories/51957","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA51957 - OpenStack Glance Swift Backend Password Disclosure Security Issue - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.launchpad.net/openstack/msg20517.html","name":"https://lists.launchpad.net/openstack/msg20517.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[OSSA 2013-002] Backend password leak in Glance error\tmessage (CVE-2013-0212) : Mailing list archive : openstack team in Launchpad","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2013:0209","name":"MISC:https://access.redhat.com/errata/RHSA-2013:0209","refsource":"MITRE","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/security/cve/CVE-2013-0212","name":"MISC:https://access.redhat.com/security/cve/CVE-2013-0212","refsource":"MITRE","tags":[],"title":"access.redhat.com | CVE-2013-0212","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-0212","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-0212","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"212","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"11.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"212","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"12.04","cpe7":"-","cpe8":"lts","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"212","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"12.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"212","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openstack","cpe5":"image_registry_and_delivery_service_\\(glance\\)","cpe6":"2012.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"212","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openstack","cpe5":"image_registry_and_delivery_service_\\(glance\\)","cpe6":"2012.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"212","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openstack","cpe5":"image_registry_and_delivery_service_\\(glance\\)","cpe6":"2012.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"212","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openstack","cpe5":"image_registry_and_delivery_service_\\(glance\\)","cpe6":"2012.2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T14:18:09.592Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/openstack/glance/commit/96a470be64adcef97f235ca96ed3c59ed954a4c1"},{"name":"[openstack] 20130129 [OSSA 2013-002] Backend password leak in Glance error message (CVE-2013-0212)","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://lists.launchpad.net/openstack/msg20517.html"},{"name":"USN-1710-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://ubuntu.com/usn/usn-1710-1"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/openstack/glance/commit/37d4d96bf88c2bf3e7e9511b5e321cf4bed364b7"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugs.launchpad.net/glance/+bug/1098962"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://launchpad.net/glance/+milestone/2012.2.3"},{"name":"[oss-security] 20130129 [OSSA 2013-002] Backend password leak in Glance error message (CVE-2013-0212)","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2013/01/29/10"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=902964"},{"name":"RHSA-2013:0209","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0209.html"},{"name":"51990","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/51990"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/openstack/glance/commit/e96273112b5b5da58d970796b7cfce04c5030a89"},{"name":"51957","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/51957"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2013-02-24T21:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/openstack/glance/commit/96a470be64adcef97f235ca96ed3c59ed954a4c1"},{"name":"[openstack] 20130129 [OSSA 2013-002] Backend password leak in Glance error message (CVE-2013-0212)","tags":["mailing-list","x_refsource_MLIST"],"url":"https://lists.launchpad.net/openstack/msg20517.html"},{"name":"USN-1710-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://ubuntu.com/usn/usn-1710-1"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/openstack/glance/commit/37d4d96bf88c2bf3e7e9511b5e321cf4bed364b7"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugs.launchpad.net/glance/+bug/1098962"},{"tags":["x_refsource_CONFIRM"],"url":"https://launchpad.net/glance/+milestone/2012.2.3"},{"name":"[oss-security] 20130129 [OSSA 2013-002] Backend password leak in Glance error message (CVE-2013-0212)","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2013/01/29/10"},{"tags":["x_refsource_MISC"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=902964"},{"name":"RHSA-2013:0209","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0209.html"},{"name":"51990","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/51990"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/openstack/glance/commit/e96273112b5b5da58d970796b7cfce04c5030a89"},{"name":"51957","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/51957"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2013-0212","datePublished":"2013-02-24T21:00:00.000Z","dateReserved":"2012-12-06T00:00:00.000Z","dateUpdated":"2024-08-06T14:18:09.592Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-02-24 21:55:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openstack:image_registry_and_delivery_service_\\(glance\\):2012.1:*:*:*:*:*:*:*","matchCriteriaId":"CD405A64-CF2D-46A0-B19F-5633E0DE1427"},{"vulnerable":true,"criteria":"cpe:2.3:a:openstack:image_registry_and_delivery_service_\\(glance\\):2012.2:*:*:*:*:*:*:*","matchCriteriaId":"936ABA46-0574-4A7F-A11D-193B32747A90"},{"vulnerable":true,"criteria":"cpe:2.3:a:openstack:image_registry_and_delivery_service_\\(glance\\):2012.2.1:*:*:*:*:*:*:*","matchCriteriaId":"E022F41C-3239-4663-9129-E8A871EA5B77"},{"vulnerable":true,"criteria":"cpe:2.3:a:openstack:image_registry_and_delivery_service_\\(glance\\):2012.2.2:*:*:*:*:*:*:*","matchCriteriaId":"09ACB383-AA30-4E23-A85E-A68E0A72B596"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*","matchCriteriaId":"E4174F4F-149E-41A6-BBCC-D01114C05F38"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*","matchCriteriaId":"F5D324C4-97C7-49D3-A809-9EAD4B690C69"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*","matchCriteriaId":"E2076871-2E80-4605-A470-A41C1A8EC7EE"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"212","Ordinal":"1","Title":"CVE-2013-0212","CVE":"CVE-2013-0212","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"212","Ordinal":"1","NoteData":"store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.","Type":"Description","Title":"CVE-2013-0212"},{"CveYear":"2013","CveId":"212","Ordinal":"2","NoteData":"2013-02-24","Type":"Other","Title":"Published"}]}}}