CVE-2013-4428

low
Published 2013-10-27 · Modified 2026-04-29
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-4428

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://launchpad.net/glance/+milestone/2013.2

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://launchpad.net/glance/+milestone/2013.1.4

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2013.2-1
debian debianbullseyefixed2013.2-1
debian debianforkyfixed2013.2-1
debian debiansidfixed2013.2-1
debian debiantrixiefixed2013.2-1
ubuntu ubuntu12.10affected
ubuntu ubuntu13.04affected

Application impact

VendorProductVersionsFixed
openstackglance{"startIncluding":"2012.2","endIncluding":"2012.2.4"}
openstackglance2013.2

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.