CVE-2013-4428: Canonical Ubuntu Linux

Low severity, CVSS 3.5. EPSS: 3.1% chance of exploitation in the next 30 days.

OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.

Affected products

  • Canonical Ubuntu Linux: version 12.10 only; version 13.04 only
  • Openstack Glance: from 2012.2, up to and including 2012.2.4; from 2013.1, before 2013.1.4 (fixed in 2013.1.4); version 2013.2 only

Published 2013-10-27. Last modified 2026-06-16.