Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-5252

Опубликовано: 25 июл. 2014
Источник: redhat
CVSS2: 4.9
EPSS Низкий

Описание

The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a verification (1) GET or (2) HEAD request to v3/auth/tokens/.

A flaw was found in keystone revocation events that resulted in the "issued_at" time being updated when a token created by the V2 API was processed by the V3 API. This could allow a user to evade token revocation. Only OpenStack Identity setups configured to make use of revocation events and UUID tokens were affected.

Отчет

This issue does not affected openstack-keystone as shipped with Red Hat Enterprise Linux OpenStack Platform 4.0.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 4openstack-keystoneNot affected
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6openstack-keystoneFixedRHSA-2014:112202.09.2014
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7openstack-keystoneFixedRHSA-2014:112102.09.2014

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-697->CWE-613
https://bugzilla.redhat.com/show_bug.cgi?id=1127250openstack-keystone: token expiration date stored incorrectly

EPSS

Процентиль: 52%
0.00287
Низкий

4.9 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a verification (1) GET or (2) HEAD request to v3/auth/tokens/.

nvd
больше 11 лет назад

The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a verification (1) GET or (2) HEAD request to v3/auth/tokens/.

debian
больше 11 лет назад

The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 ...

CVSS3: 6.5
github
больше 3 лет назад

OpenStack Identity (Keystone) UUID v2 tokens does not expire with revocation events

EPSS

Процентиль: 52%
0.00287
Низкий

4.9 Medium

CVSS2