CVE-2013-1840

low
Published 2013-03-22 · Modified 2026-05-21
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-1840

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/52565

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2012.1.1-5
debian debianbullseyefixed2012.1.1-5
debian debianforkyfixed2012.1.1-5
debian debiansidfixed2012.1.1-5
debian debiantrixiefixed2012.1.1-5

Package impact

EcosystemPackageVulnerableFixed
python PyPIglance<11.0.0a011.0.0a0
python PyPIglance<=v1

Application impact

VendorProductVersionsFixed
openstackglancev1
openstackessex2012.1
openstackfolsom2012.2
aws amazons3_store-
openstackswift-

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.