Keystone
OpenStack · 44 CVEs
openstack-keystone: cache backend password leak in log (OSSA 2015-008)
May 12, 2015
openstack-keystone: user and group id mismatch
Nov 3, 2014
openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id
Oct 26, 2014
openstack-keystone: configuration data information leak through Keystone catalog
Oct 2, 2014
openstack-keystone: domain-scoped tokens don't get revoked
Aug 25, 2014
openstack-keystone: token expiration date stored incorrectly
Aug 25, 2014
openstack-keystone: revocation events are broken with mysql
Aug 25, 2014
openstack-keystone: privilege escalation through trust chained delegation
Jun 17, 2014
OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption an…
Jun 2, 2014
openstack-keystone: denial of service via V3 API authentication chaining
Apr 15, 2014
openstack-keystone: trustee token revocation does not work with memcache backend
Apr 1, 2014
Keystone: trust circumvention through EC2-style tokens
Dec 14, 2013
OpenStack: Keystone disabling a tenant does not disable a user token
Sep 30, 2013
OpenStack: Keystone Token revocation failure using Keystone memcache/KVS backends
Sep 23, 2013
openstack-keystone: Authentication bypass when using LDAP backend
Aug 20, 2013
OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately rev…
May 21, 2013
keystone: DEBUG level LDAP password disclosure in log files
May 21, 2013
Keystone: EC2-style authentication accepts disabled user/tenants
Apr 12, 2013
Keystone: openstack keystone: denial of service via large http request with long tenant name
Apr 12, 2013
Keystone: denial of service through invalid token requests
Feb 24, 2013
OpenStack: Keystone /etc/keystone/ec2rc secret key exposure
Dec 26, 2012
2012.1.1: fails to raise Unauthorized user error for disabled tenant
Oct 9, 2012
2012.1.1: fails to validate tokens in Admin API
Oct 9, 2012
OpenStack-Keystone: role revocation token issues
Sep 18, 2012
OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly…
Jul 31, 2012
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2015-3646 | openstack-keystone: cache backend password leak in log (OSSA 2015-008) | MEDIUM | 2.88% | May 12, 2015 |
| CVE-2014-0204 | openstack-keystone: user and group id mismatch | MEDIUM | 1.40% | Nov 3, 2014 |
| CVE-2014-3520 | openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id | MEDIUM | 1.91% | Oct 26, 2014 |
| CVE-2014-3621 | openstack-keystone: configuration data information leak through Keystone catalog | MEDIUM | 2.13% | Oct 2, 2014 |
| CVE-2014-5253 | openstack-keystone: domain-scoped tokens don't get revoked | HIGH | 1.49% | Aug 25, 2014 |
| CVE-2014-5252 | openstack-keystone: token expiration date stored incorrectly | HIGH | 1.52% | Aug 25, 2014 |
| CVE-2014-5251 | openstack-keystone: revocation events are broken with mysql | HIGH | 1.59% | Aug 25, 2014 |
| CVE-2014-3476 | openstack-keystone: privilege escalation through trust chained delegation | MEDIUM | 2.33% | Jun 17, 2014 |
| CVE-2013-2014 | OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests. | MEDIUM | 3.27% | Jun 2, 2014 |
| CVE-2014-2828 | openstack-keystone: denial of service via V3 API authentication chaining | HIGH | 3.22% | Apr 15, 2014 |
| CVE-2014-2237 | openstack-keystone: trustee token revocation does not work with memcache backend | HIGH | 1.37% | Apr 1, 2014 |
| CVE-2013-6391 | Keystone: trust circumvention through EC2-style tokens | MEDIUM | 2.24% | Dec 14, 2013 |
| CVE-2013-4222 | OpenStack: Keystone disabling a tenant does not disable a user token | MEDIUM | 1.89% | Sep 30, 2013 |
| CVE-2013-4294 | OpenStack: Keystone Token revocation failure using Keystone memcache/KVS backends | MEDIUM | 2.70% | Sep 23, 2013 |
| CVE-2013-2157 | openstack-keystone: Authentication bypass when using LDAP backend | MEDIUM | 3.13% | Aug 20, 2013 |
| CVE-2013-2059 | OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleti… | MEDIUM | 2.47% | May 21, 2013 |
| CVE-2013-2006 | keystone: DEBUG level LDAP password disclosure in log files | LOW | 0.61% | May 21, 2013 |
| CVE-2013-0282 | Keystone: EC2-style authentication accepts disabled user/tenants | MEDIUM | 1.76% | Apr 12, 2013 |
| CVE-2013-0270 | Keystone: openstack keystone: denial of service via large http request with long tenant name | MEDIUM | 3.16% | Apr 12, 2013 |
| CVE-2013-0247 | Keystone: denial of service through invalid token requests | MEDIUM | 3.24% | Feb 24, 2013 |
| CVE-2012-5483 | OpenStack: Keystone /etc/keystone/ec2rc secret key exposure | LOW | 0.34% | Dec 26, 2012 |
| CVE-2012-4457 | 2012.1.1: fails to raise Unauthorized user error for disabled tenant | MEDIUM | 2.29% | Oct 9, 2012 |
| CVE-2012-4456 | 2012.1.1: fails to validate tokens in Admin API | HIGH | 4.00% | Oct 9, 2012 |
| CVE-2012-4413 | OpenStack-Keystone: role revocation token issues | MEDIUM | 1.90% | Sep 18, 2012 |
| CVE-2012-3426 | OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows… | MEDIUM | 2.28% | Jul 31, 2012 |
Showing 26 to 44 of 44 CVEs