PT-2020-13209 · Openstack+1 · Openstack Keystone+1

Kay

·

Published

2020-05-06

·

Updated

2022-05-24

·

CVE-2020-12692

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Keystone versions prior to 15.0.1 OpenStack Keystone version 16.0.0
Description An issue was discovered in the EC2 API of OpenStack Keystone, where it lacks a signature TTL check for AWS Signature V4. This allows an attacker to sniff the Authorization header and then use it to reissue an OpenStack token an unlimited number of times.
Recommendations For OpenStack Keystone versions prior to 15.0.1, update to version 15.0.1 or later to resolve the issue. For OpenStack Keystone version 16.0.0, consider disabling the EC2 API until a patch is available. As a temporary workaround, restrict access to the Authorization header to minimize the risk of exploitation.

Fix

Missing Encryption of Sensitive Data

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12692
DSA-4679-1
GHSA-RQW2-HHRF-7936
PYSEC-2020-56
RHSA-2020:2732
RHSA-2020:3102
RHSA-2020:3105
USN-4480-1

Affected Products

Openstack Keystone
Ubuntu