Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3476

Опубликовано: 12 июн. 2014
Источник: redhat
CVSS2: 4.9
EPSS Низкий

Описание

OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.

A flaw was found in keystone's chained delegation. A trustee able to create a delegation from a trust or an OAuth token could misuse identity impersonation to bypass the enforced scope, possibly allowing them to obtain elevated privileges to the trustor's projects and roles.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)openstack-keystoneAffected
OpenStack 3 for RHEL 6openstack-keystoneFixedRHSA-2014:099431.07.2014
OpenStack 4 for RHEL 6openstack-keystoneFixedRHSA-2014:099431.07.2014

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1104524openstack-keystone: privilege escalation through trust chained delegation

EPSS

Процентиль: 82%
0.02308
Низкий

4.9 Medium

CVSS2

Связанные уязвимости

ubuntu
около 12 лет назад

OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.

nvd
около 12 лет назад

OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.

debian
около 12 лет назад

OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, ...

github
около 4 лет назад

OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege

EPSS

Процентиль: 82%
0.02308
Низкий

4.9 Medium

CVSS2