Show filters
63 Total Results
Displaying 21-30 of 63
Sort by:
Attacker Value
Unknown

CVE-2012-1572

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space
Attacker Value
Unknown

CVE-2013-2255

Disclosure Date: November 01, 2019 (last updated November 27, 2024)
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
Attacker Value
Unknown

CVE-2018-20170

Disclosure Date: December 17, 2018 (last updated November 08, 2023)
OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POST /v3/auth/tokens request. NOTE: the vendor's position is that this is a hardening opportunity, and not necessarily an issue that should have an OpenStack Security Advisory
0
Attacker Value
Unknown

CVE-2018-14432

Disclosure Date: July 31, 2018 (last updated November 27, 2024)
In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated user may discover projects they have no authority to access, leaking all projects in the deployment and their attributes. Only Keystone with the /v3/OS-FEDERATION endpoint enabled via policy.json is affected.
0
Attacker Value
Unknown

CVE-2015-9240

Disclosure Date: May 29, 2018 (last updated November 26, 2024)
Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched. A correct password is still required to complete sign in.
0
Attacker Value
Unknown

CVE-2017-16570

Disclosure Date: November 06, 2017 (last updated November 26, 2024)
KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_03. In other words, it fails to reject requests that lack an x-csrf-token header.
0
Attacker Value
Unknown

CVE-2017-15881

Disclosure Date: October 24, 2017 (last updated November 26, 2024)
Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web script or HTML via the "content brief" or "content extended" field, a different vulnerability than CVE-2017-15878.
Attacker Value
Unknown

CVE-2017-15879

Disclosure Date: October 24, 2017 (last updated November 26, 2024)
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before 4.0.0-beta.7 via a value that is mishandled in a CSV export.
0
Attacker Value
Unknown

CVE-2017-15878

Disclosure Date: October 24, 2017 (last updated November 26, 2024)
A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us feature.
0
Attacker Value
Unknown

CVE-2015-7546

Disclosure Date: February 03, 2016 (last updated November 25, 2024)
The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly invalidate authorization tokens when using the PKI or PKIZ token providers, which allows remote authenticated users to bypass intended access restrictions and gain access to cloud resources by manipulating byte fields within a revoked token.