Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3fpm-8w39-5p69

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.

EPSS

Процентиль: 65%
0.00498
Низкий

Дефекты

CWE-269

Связанные уязвимости

ubuntu
около 12 лет назад

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.

redhat
около 12 лет назад

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.

nvd
около 12 лет назад

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.

debian
около 12 лет назад

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013. ...

EPSS

Процентиль: 65%
0.00498
Низкий

Дефекты

CWE-269