Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-0105

Опубликовано: 15 апр. 2014
Источник: nvd
CVSS2: 6
EPSS Низкий

Описание

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openstack:python-keystoneclient:*:*:*:*:*:*:*:*
Версия до 0.4.2 (включая)
cpe:2.3:a:openstack:python-keystoneclient:0.2.2:*:*:*:*:*:*:*
cpe:2.3:a:openstack:python-keystoneclient:0.2.3:*:*:*:*:*:*:*
cpe:2.3:a:openstack:python-keystoneclient:0.2.4:*:*:*:*:*:*:*
cpe:2.3:a:openstack:python-keystoneclient:0.3.0:*:*:*:*:*:*:*
cpe:2.3:a:openstack:python-keystoneclient:0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:python-keystoneclient:0.3.2:*:*:*:*:*:*:*

EPSS

Процентиль: 58%
0.00371
Низкий

6 Medium

CVSS2

Дефекты

CWE-255

Связанные уязвимости

ubuntu
почти 12 лет назад

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."

redhat
почти 12 лет назад

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."

debian
почти 12 лет назад

The auth_token middleware in the OpenStack Python client library for K ...

CVSS3: 6
github
больше 3 лет назад

python-keystoneclient vulnerable to context confusion in Keystone auth_token middleware

EPSS

Процентиль: 58%
0.00371
Низкий

6 Medium

CVSS2

Дефекты

CWE-255