PT-2014-3479 · Eventlet+2 · Eventlet+2

Kieran Spear

+1

·

Published

2014-04-15

·

Updated

2022-05-17

·

CVE-2014-0105

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions python-keystoneclient versions prior to 0.7.0
Description A context confusion issue exists in the Keystone auth token middleware, allowing remote authenticated users to potentially gain privileges under certain circumstances. This is related to a bad interaction between eventlet and python-memcached. By making repeated requests with sufficient load on the target system, an authenticated user may assume another authenticated user's complete identity and multi-tenant authorizations, potentially resulting in privilege escalation. This issue affects keystone middleware setups using auth token with memcache.
Recommendations For versions prior to 0.7.0, update to version 0.7.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of memcache with the auth token middleware or restricting the load on the target system to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-0105
GHSA-GWVQ-RGQF-993F
OPENSUSE-SU-2024:10471-1
PYSEC-2014-70
RHSA-2014:0382
RHSA-2014:0409
RHSA-2014:0442

Affected Products

Eventlet
Python-Keystoneclient
Python-Memcached