OpenStack Keystone Trustee Token Revocation Failure Security Bypass Vulnerability
BID:65895
Info
OpenStack Keystone Trustee Token Revocation Failure Security Bypass Vulnerability
| Bugtraq ID: | 65895 |
| Class: | Design Error |
| CVE: |
CVE-2014-2237 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2013 12:00AM |
| Updated: | May 07 2015 05:12PM |
| Credit: | Morgan Fainberg |
| Vulnerable: |
SuSE Cloud 3.0 Redhat OpenStack 4.0 Redhat OpenStack 3.0 OpenStack Keystone 2013.1.2 OpenStack Keystone 2013.1.1 OpenStack Keystone 2013.2.2 OpenStack Keystone 2013.2.1 OpenStack Keystone 2013.2.0 OpenStack Keystone 2013.2 OpenStack Keystone 2013.1.4 OpenStack Keystone 2013.1.3 OpenStack Keystone 2013.1 IBM SmartCloud Orchestrator 2.3 FP1 IBM SmartCloud Orchestrator 2.3 |
| Not Vulnerable: |
IBM SmartCloud Orchestrator 2.3 FP1 iFix4 |
Discussion
OpenStack Keystone Trustee Token Revocation Failure Security Bypass Vulnerability
Keystone is prone to a security-bypass vulnerability.
Successful exploits may allow authenticated attackers to bypass certain intended security restrictions and perform unauthorized actions which may aid in launching further attacks.
Keystone 2013.1 to 2013.1.4 and 2013.2 to 2013.2.2 are affected.
Keystone is prone to a security-bypass vulnerability.
Successful exploits may allow authenticated attackers to bypass certain intended security restrictions and perform unauthorized actions which may aid in launching further attacks.
Keystone 2013.1 to 2013.1.4 and 2013.2 to 2013.2.2 are affected.
Exploit / POC
OpenStack Keystone Trustee Token Revocation Failure Security Bypass Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
OpenStack Keystone Trustee Token Revocation Failure Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OpenStack Keystone Trustee Token Revocation Failure Security Bypass Vulnerability
References:
References: