Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0105

Опубликовано: 15 апр. 2014
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 6

Описание

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."

РелизСтатусПримечание
devel

not-affected

1:2014.1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [1:2014.1-0ubuntu1]]
esm-infra/xenial

not-affected

1:2014.1-0ubuntu1
lucid

DNE

precise

ignored

end of life
precise/esm

DNE

precise was needed
quantal

ignored

end of life
saucy

not-affected

1:2013.2.3-0ubuntu1
trusty

not-affected

1:2014.1-0ubuntu1
trusty/esm

DNE

trusty was not-affected [1:2014.1-0ubuntu1]

Показывать по

РелизСтатусПримечание
devel

not-affected

1:0.7.1-ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [1:0.7.1-ubuntu1]]
esm-infra/xenial

not-affected

1:0.7.1-ubuntu1
lucid

DNE

precise

not-affected

code-not-present
precise/esm

DNE

precise was not-affected [code-not-present]
quantal

not-affected

code-not-present
saucy

ignored

end of life
trusty

not-affected

1:0.7.1-ubuntu1
trusty/esm

DNE

trusty was not-affected [1:0.7.1-ubuntu1]

Показывать по

Ссылки на источники

EPSS

Процентиль: 58%
0.00371
Низкий

6 Medium

CVSS2

Связанные уязвимости

redhat
почти 12 лет назад

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."

nvd
почти 12 лет назад

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."

debian
почти 12 лет назад

The auth_token middleware in the OpenStack Python client library for K ...

CVSS3: 6
github
больше 3 лет назад

python-keystoneclient vulnerable to context confusion in Keystone auth_token middleware

EPSS

Процентиль: 58%
0.00371
Низкий

6 Medium

CVSS2