PYSEC-2013-46

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/glance/PYSEC-2013-46.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2013-46
Aliases
Published
2013-03-22T21:55:01.487Z
Modified
2026-05-21T15:00:13.413385477Z
Summary
[none]
Details

The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.

References

Affected packages

PyPI / glance

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
v1

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/glance/PYSEC-2013-46.yaml"