Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-7144

Опубликовано: 02 окт. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

РелизСтатусПримечание
devel

not-affected

1:0.11.2-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1:0.7.1-ubuntu1.2]]
lucid

DNE

precise

not-affected

code not present
trusty

released

1:0.7.1-ubuntu1.2
trusty/esm

DNE

trusty was released [1:0.7.1-ubuntu1.2]
upstream

released

1:0.10.1-2
utopic

ignored

end of life
vivid

not-affected

1:0.11.2-0ubuntu1

Показывать по

РелизСтатусПримечание
devel

not-affected

1.3.1-0ubuntu2
esm-infra-legacy/trusty

DNE

lucid

DNE

precise

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

1.0.0-3
utopic

ignored

end of life
vivid

not-affected

1.3.1-0ubuntu2

Показывать по

EPSS

Процентиль: 58%
0.00365
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 11 лет назад

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

nvd
больше 11 лет назад

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

debian
больше 11 лет назад

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x befo ...

CVSS3: 5.9
github
больше 3 лет назад

OpenStack keystonemiddleware does not verify certificate

EPSS

Процентиль: 58%
0.00365
Низкий

4.3 Medium

CVSS2