Total vulnerabilities in the database
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
Software | From | Fixed in |
---|---|---|
openstack / glance | 2012.2 | 2012.2.4.x |
openstack / glance | 2013.1 | 2013.1.4 |
openstack / glance | 2013.2-milestone1 | 2013.2-milestone1.x |
openstack / glance | 2013.2-milestone2 | 2013.2-milestone2.x |
openstack / glance | 2013.2-milestone3 | 2013.2-milestone3.x |
canonical / ubuntu_linux | 13.04 | 13.04.x |
canonical / ubuntu_linux | 12.10 | 12.10.x |