PT-2014-3479 · Eventlet+2 · Eventlet+2

Kieran Spear

+1

·

Publicado

2014-04-15

·

Atualizado

2022-05-17

·

CVE-2014-0105

CVSS v2.0

6.0

Média

VetorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions python-keystoneclient versions prior to 0.7.0
Description A context confusion issue exists in the Keystone auth token middleware, allowing remote authenticated users to potentially gain privileges under certain circumstances. This is related to a bad interaction between eventlet and python-memcached. By making repeated requests with sufficient load on the target system, an authenticated user may assume another authenticated user's complete identity and multi-tenant authorizations, potentially resulting in privilege escalation. This issue affects keystone middleware setups using auth token with memcache.
Recommendations For versions prior to 0.7.0, update to version 0.7.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of memcache with the auth token middleware or restricting the load on the target system to minimize the risk of exploitation.

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-0105
GHSA-GWVQ-RGQF-993F
OPENSUSE-SU-2024:10471-1
PYSEC-2014-70
RHSA-2014:0382
RHSA-2014:0409
RHSA-2014:0442

Produtos afetados

Eventlet
Python-Keystoneclient
Python-Memcached