Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-3621

Опубликовано: 02 окт. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4

Описание

The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.

РелизСтатусПримечание
devel

released

1:2014.2~rc1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1:2014.1.3-0ubuntu2.1]]
esm-infra-legacy/xenial

released

1:2014.2~rc1-0ubuntu1
esm-infra/xenial

released

1:2014.2~rc1-0ubuntu1
lucid

DNE

precise

ignored

end of life
precise/esm

DNE

precise was needed
trusty

released

1:2014.1.3-0ubuntu2.1
trusty/esm

DNE

trusty was released [1:2014.1.3-0ubuntu2.1]
upstream

released

2013.2.3, 2014.1.2.1

Показывать по

EPSS

Процентиль: 80%
0.02109
Низкий

4 Medium

CVSS2

Связанные уязвимости

redhat
почти 12 лет назад

The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.

nvd
почти 12 лет назад

The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.

debian
почти 12 лет назад

The catalog url replacement in OpenStack Identity (Keystone) before 20 ...

github
больше 4 лет назад

OpenStack Identity Keystone Exposure of Sensitive Information

EPSS

Процентиль: 80%
0.02109
Низкий

4 Medium

CVSS2