Keystone

OpenStack · 44 CVEs

CVE-2015-3646
MEDIUM

openstack-keystone: cache backend password leak in log (OSSA 2015-008)

May 12, 2015

CVE-2014-0204
MEDIUM

openstack-keystone: user and group id mismatch

Nov 3, 2014

CVE-2014-3520
MEDIUM

openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id

Oct 26, 2014

CVE-2014-3621
MEDIUM

openstack-keystone: configuration data information leak through Keystone catalog

Oct 2, 2014

CVE-2014-5253
HIGH

openstack-keystone: domain-scoped tokens don't get revoked

Aug 25, 2014

CVE-2014-5252
HIGH

openstack-keystone: token expiration date stored incorrectly

Aug 25, 2014

CVE-2014-5251
HIGH

openstack-keystone: revocation events are broken with mysql

Aug 25, 2014

CVE-2014-3476
MEDIUM

openstack-keystone: privilege escalation through trust chained delegation

Jun 17, 2014

CVE-2013-2014
MEDIUM

OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption an…

Jun 2, 2014

CVE-2014-2828
HIGH

openstack-keystone: denial of service via V3 API authentication chaining

Apr 15, 2014

CVE-2014-2237
HIGH

openstack-keystone: trustee token revocation does not work with memcache backend

Apr 1, 2014

CVE-2013-6391
MEDIUM

Keystone: trust circumvention through EC2-style tokens

Dec 14, 2013

CVE-2013-4222
MEDIUM

OpenStack: Keystone disabling a tenant does not disable a user token

Sep 30, 2013

CVE-2013-4294
MEDIUM

OpenStack: Keystone Token revocation failure using Keystone memcache/KVS backends

Sep 23, 2013

CVE-2013-2157
MEDIUM

openstack-keystone: Authentication bypass when using LDAP backend

Aug 20, 2013

CVE-2013-2059
MEDIUM

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately rev…

May 21, 2013

CVE-2013-2006
LOW

keystone: DEBUG level LDAP password disclosure in log files

May 21, 2013

CVE-2013-0282
MEDIUM

Keystone: EC2-style authentication accepts disabled user/tenants

Apr 12, 2013

CVE-2013-0270
MEDIUM

Keystone: openstack keystone: denial of service via large http request with long tenant name

Apr 12, 2013

CVE-2013-0247
MEDIUM

Keystone: denial of service through invalid token requests

Feb 24, 2013

CVE-2012-5483
LOW

OpenStack: Keystone /etc/keystone/ec2rc secret key exposure

Dec 26, 2012

CVE-2012-4457
MEDIUM

2012.1.1: fails to raise Unauthorized user error for disabled tenant

Oct 9, 2012

CVE-2012-4456
HIGH

2012.1.1: fails to validate tokens in Admin API

Oct 9, 2012

CVE-2012-4413
MEDIUM

OpenStack-Keystone: role revocation token issues

Sep 18, 2012

CVE-2012-3426
MEDIUM

OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly…

Jul 31, 2012

Showing 26 to 44 of 44 CVEs