Show filters
63 Total Results
Displaying 31-40 of 63
Sort by:
Attacker Value
Unknown

CVE-2015-3646

Disclosure Date: May 12, 2015 (last updated October 05, 2023)
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
0
Attacker Value
Unknown

CVE-2015-1852

Disclosure Date: April 17, 2015 (last updated October 05, 2023)
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.
0
Attacker Value
Unknown

CVE-2014-0204

Disclosure Date: November 03, 2014 (last updated October 05, 2023)
OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.
0
Attacker Value
Unknown

CVE-2014-3520

Disclosure Date: October 26, 2014 (last updated October 05, 2023)
OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to an unauthorized project for which the trustor has certain roles via the project ID in a V2 API trust token request.
0
Attacker Value
Unknown

CVE-2014-7144

Disclosure Date: October 02, 2014 (last updated October 05, 2023)
OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-3621

Disclosure Date: October 02, 2014 (last updated October 05, 2023)
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
0
Attacker Value
Unknown

CVE-2014-5252

Disclosure Date: August 25, 2014 (last updated October 05, 2023)
The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a verification (1) GET or (2) HEAD request to v3/auth/tokens/.
0
Attacker Value
Unknown

CVE-2014-5251

Disclosure Date: August 25, 2014 (last updated October 05, 2023)
The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.
0
Attacker Value
Unknown

CVE-2014-5253

Disclosure Date: August 25, 2014 (last updated October 05, 2023)
OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domain.
0
Attacker Value
Unknown

CVE-2014-3476

Disclosure Date: June 17, 2014 (last updated October 05, 2023)
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.
0