OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Image_registry_and_delivery_service_(glance) | Openstack | 2013.2 (including) | 2013.2 (including) |
Image_registry_and_delivery_service_(glance) | Openstack | 2013.2.1 (including) | 2013.2.1 (including) |
OpenStack 4 for RHEL 6 | RedHat | openstack-glance-0:2013.2.2-2.el6ost | * |
Glance | Ubuntu | upstream | * |