Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-6391

Опубликовано: 14 дек. 2013
Источник: nvd
CVSS2: 5.8
EPSS Низкий

Описание

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
Версия от 2013.2 (включая) до 2013.2.1 (исключая)
Конфигурация 2
cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:a:redhat:openstack:4.0:*:*:*:*:*:*:*

EPSS

Процентиль: 65%
0.00498
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-269

Связанные уязвимости

ubuntu
около 12 лет назад

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.

redhat
около 12 лет назад

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.

debian
около 12 лет назад

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013. ...

github
больше 3 лет назад

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.

EPSS

Процентиль: 65%
0.00498
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-269
Уязвимость CVE-2013-6391