Information Disclosure in OpenStack Glance Due to Misconfiguration
CVE-2013-0212

Currently unrated

Key Information:

Vendor
Openstack
Vendor
CVE Published:
24 February 2013

Badges

👾 Exploit Exists🟡 Public PoC

Summary

In certain versions of OpenStack Glance running in Swift single tenant mode, misconfigured endpoints can lead to a serious information disclosure issue. When the endpoint is either misconfigured or deemed unusable, the system inadvertently logs sensitive authentication details, including usernames and passwords, in cleartext. This vulnerability allows remote authenticated users to access error messages that contain this sensitive information, posing a significant security risk.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.