Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-7144

Опубликовано: 02 окт. 2014
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openstack:keystonemiddleware:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystonemiddleware:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystonemiddleware:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:python-keystoneclient:*:*:*:*:*:*:*:*
Версия до 0.10.1 (включая)

EPSS

Процентиль: 58%
0.00365
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-310

Связанные уязвимости

ubuntu
больше 11 лет назад

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

redhat
больше 11 лет назад

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

debian
больше 11 лет назад

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x befo ...

CVSS3: 5.9
github
больше 3 лет назад

OpenStack keystonemiddleware does not verify certificate

EPSS

Процентиль: 58%
0.00365
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-310