exception.BadStoreUri exposes sensitive information to end users

Bug #1012268 reported by Brian Waldon on 2012-06-12
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Glance
High
Alex Meade
Essex
High
Brian Waldon
glance (Ubuntu)
Undecided
Unassigned
Precise
Undecided
Unassigned

Bug Description

Wherever BadStoreUri is translated to a HTTPBadRequest and returned to the user, the store uri and some relevant explanation are given to the user. This will typically contain some of the configured swift credentials, which we do not want to present to the end-user.

Related branches

Brian Waldon (bcwaldon) on 2012-06-14
Changed in glance:
assignee: nobody → Alex Meade (alex-meade)
Alex Meade (alex-meade) on 2012-06-14
Changed in glance:
status: Confirmed → In Progress

Reviewed: https://review.openstack.org/8562
Committed: http://github.com/openstack/glance/commit/ed16167425c5a2a610ce503c3084bb3b2a03ae63
Submitter: Jenkins
Branch: master

commit ed16167425c5a2a610ce503c3084bb3b2a03ae63
Author: Alex Meade <email address hidden>
Date: Thu Jun 14 15:09:03 2012 -0400

    Stop revealing sensitive store info

    Use simpler error messages and log the details.

    Fixes bug: 1012268

    Change-Id: I3c4d98c81dee6676916c60e71a749037ae1edc81

Changed in glance:
status: In Progress → Fix Committed
Thierry Carrez (ttx) on 2012-07-04
Changed in glance:
status: Fix Committed → Fix Released

Reviewed: https://review.openstack.org/10793
Committed: http://github.com/openstack/glance/commit/19c07722e6437d97082176172b8ef41389676782
Submitter: Jenkins
Branch: stable/essex

commit 19c07722e6437d97082176172b8ef41389676782
Author: Brian Waldon <email address hidden>
Date: Fri Aug 3 14:11:34 2012 -0700

    Stop revealing sensitive store info

    Use simpler error messages in exception.BadStoreUri
    and log the details.

    Fixes bug 1012268 specifically for stable/essex

    Change-Id: I8676a1281bd132d282b206730b12064b50805ef1

Dave Walker (davewalker) on 2012-08-24
Changed in glance (Ubuntu):
status: New → Fix Released
Changed in glance (Ubuntu Precise):
status: New → Confirmed

Please find the attached test log from the Ubuntu Server Team's CI infrastructure. As part of the verification process for this bug, Glance has been deployed and configured across multiple nodes using precise-proposed as an installation source. After successful bring-up and configuration of the cluster, a number of exercises and smoke tests have be invoked to ensure the updated package did not introduce any regressions. A number of test iterations were carried out to catch any possible transient errors.

Please Note the list of installed packages at the top and bottom of the report.

For records of upstream test coverage of this update, please see the Jenkins links in the comments of the relevant upstream code-review(s):

Trunk review: https://review.openstack.org/8562
Stable review: https://review.openstack.org/10793

As per the provisional Micro Release Exception granted to this package by the Technical Board, we hope this contributes toward verification of this update.

Adam Gandelman (gandelman-a) wrote :

Test coverage log.

tags: added: verification-done

The verification of this Stable Release Update has completed successfully and the package has now been released to -updates. Subsequently, the Ubuntu Stable Release Updates Team is being unsubscribed and will not receive messages about this bug report. In the event that you encounter a regression using the package from -updates please report a new bug using ubuntu-bug and tag the bug report regression-update so we can easily find any regresssions.

Launchpad Janitor (janitor) wrote :

This bug was fixed in the package glance - 2012.1.3+stable~20120821-120fcf-0ubuntu1

---------------
glance (2012.1.3+stable~20120821-120fcf-0ubuntu1) precise-proposed; urgency=low

  * New upstream snapshot. (LP: #1041120)
  * Resynchronzie with stable/essex:
    - Glance add uploads a double image if using ssl and images is smaller
      than 4k. (LP: #1007093)
    - If response.environ is None, instance fails to spawn.
      (LP: #1010560)
    - exception.BadStoreURL exposes sensitive information to end users.
      (LP: #1012268)
    - glance-cache.conf needs metadata encryption key (LP: #1012752)
    - image.upload notification doesn't report size (LP: #1018246)
    - Admins should be able to share image regardless of ownership.
      (LP: #1021054)
    - Glance scrubber date formatting fails with postgres (LP: #1022369)
    - Support zero-size image creation. (LP: #1025353)
    - Image id not contained in swift chunk debug message. (LP: #1028433)
    - qpid_heartbeat setting is ineffective. (LP: #1032314)
    - Image properties that reference image ids are not updated to UUIDs.
      (LP: #975651)
    - Migration 012_id_to_uuid attempts to convert IDs twice for non-sqlite
      databases. (LP: #975655)
    - multiprocess glance-api failed to exit when stopped by ctrl+c.
      (LP: #978130)
    - /usr/bin/glance's built-in pager breaks redirection.
      (LP: #978610)
    - Content-Length and Transfer-Encoding are mutually exclusive HTTP headers
      (LP: #981332)
    - glance add command - incorrect help text (LP: #997565)
  * debian/patches/convert_properties_to_uuid.patch: Dropped no longer
    needed.
  * debian/patches/fix-pep8-ubuntu.patch: Dropped no longer needed.
 -- Adam Gandelman <email address hidden> Fri, 24 Jun 2012 03:14:33 -0400

Changed in glance (Ubuntu Precise):
status: Confirmed → Fix Released
Thierry Carrez (ttx) on 2012-09-27
Changed in glance:
milestone: folsom-2 → 2012.2
To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers