PT-2014-6368 · Openstack+1 · Openstack Identity+1

Lance Bragstad

+1

·

Publicado

2014-08-15

·

Atualizado

2022-05-17

·

CVE-2014-5252

CVSS v4.0

7.1

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenStack Identity (Keystone) versions 2014.1.x through 2014.1.2.1 OpenStack Identity (Keystone) version Juno before Juno-3
Description The issue allows remote authenticated users to bypass token expiration and retain access. This is achieved via a verification request to the "v3/auth/tokens/" endpoint. The issued at value for UUID v2 tokens is updated, enabling continued access.
Recommendations For OpenStack Identity (Keystone) versions 2014.1.x through 2014.1.2.1, update to version 2014.1.2.1 or later to resolve the issue. For OpenStack Identity (Keystone) version Juno before Juno-3, apply the Juno-3 update to fix the problem. As a temporary workaround, consider restricting access to the "v3/auth/tokens/" endpoint to minimize the risk of exploitation.

Correção

Insufficient Session Expiration

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-5252
GHSA-V8FQ-GQ9J-3V7H
PYSEC-2014-108
RHSA-2014:1121
RHSA-2014:1122
USN-2324-1

Produtos afetados

Openstack Identity
Ubuntu