Information Disclosure in OpenStack Glance Due to Misconfiguration
CVE-2013-0212
Currently unrated
Key Information:
- Vendor
- Openstack
- Vendor
- CVE Published:
- 24 February 2013
Badges
👾 Exploit Exists🟡 Public PoC
Summary
In certain versions of OpenStack Glance running in Swift single tenant mode, misconfigured endpoints can lead to a serious information disclosure issue. When the endpoint is either misconfigured or deemed unusable, the system inadvertently logs sensitive authentication details, including usernames and passwords, in cleartext. This vulnerability allows remote authenticated users to access error messages that contain this sensitive information, posing a significant security risk.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved