Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qvpr-qm6w-6rcc

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

OpenStack Keystone intended authorization restrictions bypass

OpenStack Keystone Essex (2012.1) and Folsom (2012.2) does not properly handle EC2 tokens when the user role has been removed from a tenant, which allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for the removed user role.

Пакеты

Наименование

Keystone

pip
Затронутые версииВерсия исправления

< 8.0.0a0

8.0.0a0

EPSS

Процентиль: 79%
0.02055
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 13 лет назад

A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly handle EC2 (Elastic Compute Cloud) tokens when a user's role has been removed from a tenant. An attacker can leverage a token associated with a removed user role to gain unauthorized access.

CVSS3: 5.4
redhat
больше 13 лет назад

A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly handle EC2 (Elastic Compute Cloud) tokens when a user's role has been removed from a tenant. An attacker can leverage a token associated with a removed user role to gain unauthorized access.

CVSS3: 5.4
nvd
больше 13 лет назад

A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly handle EC2 (Elastic Compute Cloud) tokens when a user's role has been removed from a tenant. An attacker can leverage a token associated with a removed user role to gain unauthorized access.

CVSS3: 5.4
debian
больше 13 лет назад

A flaw was found in OpenStack Keystone. This vulnerability allows remo ...

EPSS

Процентиль: 79%
0.02055
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-639