CVE-2013-1840
Openstack Glance < 11.0.0a0 - Information Disclosure
Title source: ruleDescription
The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.
References (11)
Scores
EPSS
0.0034
EPSS Percentile
56.6%
Classification
CWE
CWE-200
Status
draft
Affected Products (2)
openstack/glance
pypi/glance
< 11.0.0a0PyPI
Timeline
Published
Mar 22, 2013
Tracked Since
Feb 18, 2026