MEDIUM
Keystone: trust circumvention through EC2-style tokens
Published Dec 14, 2013
5.8
MEDIUMCVSS 2.0
EPSS 2.24%
Description
The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.
Affected products
No data.
No data.
OpenStack 3 for RHEL 6
openstack-keystone-0:2013.1.5-2.el6ost
Fixed · RHSA-2014:0368
OpenStack 4 for RHEL 6
openstack-keystone-0:2013.2.1-1.el6ost
Fixed · RHSA-2014:0089
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 3 for RHEL 6 | openstack-keystone-0:2013.1.5-2.el6ost | Fixed | RHSA-2014:0368 |
| OpenStack 4 for RHEL 6 | openstack-keystone-0:2013.2.1-1.el6ost | Fixed | RHSA-2014:0089 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (13)
- http://rhn.redhat.com/errata/RHSA-2014-0089.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://secunia.com/advisories/56079 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/56154 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/12/11/7 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/64253 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2061-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2013-6391 Vendor Advisory
- https://bugs.launchpad.net/keystone/+bug/1242597 x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1039164 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-6215 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89657 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2013-6391
- https://www.cve.org/CVERecord?id=CVE-2013-6391
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 14, 2013
Updated Aug 6, 2024
Reserved Nov 4, 2013
Link CVE-2013-6391
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2013-6215 Assigner redhat
Published Dec 14, 2013
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2013-6215