Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1852

Опубликовано: 15 апр. 2015
Источник: redhat
CVSS2: 6.8

Описание

The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.

It was discovered that some items in the S3Token paste configuration as used by python-keystonemiddleware (formerly python-keystoneclient) were incorrectly evaluated as strings, an issue similar to CVE-2014-7144. If the "insecure" option were set to "false", the option would be evaluated as true, resulting in TLS connections being vulnerable to man-in-the-middle attacks. Note: the "insecure" option defaults to false, so setups that do not specifically define "insecure=false" are not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)python-keystoneclientNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)python-keystonemiddlewareNot affected
Red Hat OpenStack Platform 4python-keystoneclientWill not fix
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6python-keystoneclientFixedRHSA-2015:168525.08.2015
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7python-keystoneclientFixedRHSA-2015:168525.08.2015
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7python-keystoneclientFixedRHSA-2015:167724.08.2015
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7python-keystonemiddlewareFixedRHSA-2015:167724.08.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=1209527keystonemiddleware/keystoneclient: S3Token TLS cert verification option not honored

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.

nvd
почти 11 лет назад

The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.

debian
почти 11 лет назад

The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 a ...

suse-cvrf
больше 10 лет назад

Security update for python modules

suse-cvrf
больше 10 лет назад

Security update for python-keystoneclient

6.8 Medium

CVSS2