Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3476

Опубликовано: 12 июн. 2014
Источник: redhat
CVSS2: 4.9

Описание

OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.

A flaw was found in keystone's chained delegation. A trustee able to create a delegation from a trust or an OAuth token could misuse identity impersonation to bypass the enforced scope, possibly allowing them to obtain elevated privileges to the trustor's projects and roles.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)openstack-keystoneAffected
OpenStack 3 for RHEL 6openstack-keystoneFixedRHSA-2014:099431.07.2014
OpenStack 4 for RHEL 6openstack-keystoneFixedRHSA-2014:099431.07.2014

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1104524openstack-keystone: privilege escalation through trust chained delegation

4.9 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.

nvd
больше 11 лет назад

OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.

debian
больше 11 лет назад

OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, ...

github
больше 3 лет назад

OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege

4.9 Medium

CVSS2