CVE-2013-4428: Canonical Ubuntu Linux
Low severity, CVSS 3.5. EPSS: 3.1% chance of exploitation in the next 30 days.
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
Affected products
- Canonical Ubuntu Linux: version 12.10 only; version 13.04 only
- Openstack Glance: from 2012.2, up to and including 2012.2.4; from 2013.1, before 2013.1.4 (fixed in 2013.1.4); version 2013.2 only
Published 2013-10-27. Last modified 2026-06-16.