Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0105

Опубликовано: 27 мар. 2014
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1082165python-keystoneclient: Potential context confusion in Keystone middleware

EPSS

Процентиль: 58%
0.00371
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 12 лет назад

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."

nvd
почти 12 лет назад

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."

debian
почти 12 лет назад

The auth_token middleware in the OpenStack Python client library for K ...

CVSS3: 6
github
больше 3 лет назад

python-keystoneclient vulnerable to context confusion in Keystone auth_token middleware

EPSS

Процентиль: 58%
0.00371
Низкий

4.3 Medium

CVSS2