openstack-keystone: configuration data information leak through Keystone catalog
Published Oct 2, 2014
4.0
MEDIUMCVSS 2.0
EPSS 2.13%
Description
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
Affected products
No data.
Configuration 1
Configuration 2
- 14.04
Configuration 3
Running on/with
- 6.0
- 7.0
No data.
OpenStack 4 for RHEL 6
openstack-keystone-0:2013.2.4-1.el6ost
Fixed · RHSA-2014:1688
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
openstack-keystone-0:2014.1.3-2.el6ost
Fixed · RHSA-2014:1789
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7
openstack-keystone-0:2014.1.3-2.el7ost
Fixed · RHSA-2014:1790
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 4 for RHEL 6 | openstack-keystone-0:2013.2.4-1.el6ost | Fixed | RHSA-2014:1688 |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | openstack-keystone-0:2014.1.3-2.el6ost | Fixed | RHSA-2014:1789 |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | openstack-keystone-0:2014.1.3-2.el7ost | Fixed | RHSA-2014:1790 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (16)
- http://rhn.redhat.com/errata/RHSA-2014-1688.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1789.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1790.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.openwall.com/lists/oss-security/2014/09/16/10 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.ubuntu.com/usn/USN-2406-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/errata/RHSA-2014:1688
- https://access.redhat.com/errata/RHSA-2014:1789
- https://access.redhat.com/errata/RHSA-2014:1790
- https://access.redhat.com/security/cve/CVE-2014-3621 Vendor Advisory
- https://bugs.launchpad.net/keystone/+bug/1354208 x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1139937 Issue Tracking
- https://github.com/advisories/GHSA-8v8f-vc72-pmhc Advisory
- https://github.com/openstack/keystone/commit/2989ff257e4fde6a168e25b926805e700406aa80
- https://github.com/openstack/keystone/commit/52714633c9a4dae5e60279217090859aa6dbcb4f
- https://nvd.nist.gov/vuln/detail/CVE-2014-3621
- https://www.cve.org/CVERecord?id=CVE-2014-3621
Change history (0)
No recorded changes yet.