PT-2020-13209 · Openstack+1 · Openstack Keystone+1
Kay
·
Published
2020-05-06
·
Updated
2022-05-24
·
CVE-2020-12692
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Keystone versions prior to 15.0.1
OpenStack Keystone version 16.0.0
Description
An issue was discovered in the EC2 API of OpenStack Keystone, where it lacks a signature TTL check for AWS Signature V4. This allows an attacker to sniff the Authorization header and then use it to reissue an OpenStack token an unlimited number of times.
Recommendations
For OpenStack Keystone versions prior to 15.0.1, update to version 15.0.1 or later to resolve the issue.
For OpenStack Keystone version 16.0.0, consider disabling the EC2 API until a patch is available.
As a temporary workaround, restrict access to the Authorization header to minimize the risk of exploitation.
Fix
Missing Encryption of Sensitive Data
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openstack Keystone
Ubuntu