Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pxxv-rv32-2qgv

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

OpenStack Nova uses insecure keystone middleware tmpdir by default

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

Пакеты

Наименование

python-keystoneclient

pip
Затронутые версииВерсия исправления

< 0.2.4

0.2.4

EPSS

Процентиль: 10%
0.00035
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-1188

Связанные уязвимости

ubuntu
около 12 лет назад

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

redhat
больше 12 лет назад

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

nvd
около 12 лет назад

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.

debian
около 12 лет назад

keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, a ...

EPSS

Процентиль: 10%
0.00035
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-1188