Show filters
63 Total Results
Displaying 21-30 of 63
Sort by:
Attacker Value
Unknown
CVE-2012-1572
Disclosure Date: November 12, 2019 (last updated November 27, 2024)
OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space
0
Attacker Value
Unknown
CVE-2013-2255
Disclosure Date: November 01, 2019 (last updated November 27, 2024)
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
0
Attacker Value
Unknown
CVE-2018-20170
Disclosure Date: December 17, 2018 (last updated November 08, 2023)
OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POST /v3/auth/tokens request. NOTE: the vendor's position is that this is a hardening opportunity, and not necessarily an issue that should have an OpenStack Security Advisory
0
Attacker Value
Unknown
CVE-2018-14432
Disclosure Date: July 31, 2018 (last updated November 27, 2024)
In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated user may discover projects they have no authority to access, leaking all projects in the deployment and their attributes. Only Keystone with the /v3/OS-FEDERATION endpoint enabled via policy.json is affected.
0
Attacker Value
Unknown
CVE-2015-9240
Disclosure Date: May 29, 2018 (last updated November 26, 2024)
Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched. A correct password is still required to complete sign in.
0
Attacker Value
Unknown
CVE-2017-16570
Disclosure Date: November 06, 2017 (last updated November 26, 2024)
KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_03. In other words, it fails to reject requests that lack an x-csrf-token header.
0
Attacker Value
Unknown
CVE-2017-15881
Disclosure Date: October 24, 2017 (last updated November 26, 2024)
Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web script or HTML via the "content brief" or "content extended" field, a different vulnerability than CVE-2017-15878.
0
Attacker Value
Unknown
CVE-2017-15879
Disclosure Date: October 24, 2017 (last updated November 26, 2024)
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before 4.0.0-beta.7 via a value that is mishandled in a CSV export.
0
Attacker Value
Unknown
CVE-2017-15878
Disclosure Date: October 24, 2017 (last updated November 26, 2024)
A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us feature.
0
Attacker Value
Unknown
CVE-2015-7546
Disclosure Date: February 03, 2016 (last updated November 25, 2024)
The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly invalidate authorization tokens when using the PKI or PKIZ token providers, which allows remote authenticated users to bypass intended access restrictions and gain access to cloud resources by manipulating byte fields within a revoked token.
0