Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-7144

Опубликовано: 02 окт. 2014
Источник: debian
EPSS Низкий

Описание

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-keystonemiddlewarefixed1.0.0-3package
python-keystoneclientfixed1:0.10.1-2package
python-keystoneclientno-dsawheezypackage

EPSS

Процентиль: 58%
0.00365
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

redhat
больше 11 лет назад

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

nvd
больше 11 лет назад

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

CVSS3: 5.9
github
больше 3 лет назад

OpenStack keystonemiddleware does not verify certificate

EPSS

Процентиль: 58%
0.00365
Низкий