CVE
CVE-2014-3621
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
- Severity
- MEDIUM
- CVSS
- 4
- Published
- Modified
Linked Releases
| Distribution | Release | Status | Evidence |
|---|---|---|---|
| Ubuntu | 14.04.6 amd64 desktop | unknown | source |
| Ubuntu | 14.04.6 i386 desktop | unknown | source |
| Ubuntu | 14.04.6 amd64 server | unknown | source |
| Ubuntu | 14.04.6 i386 server | unknown | source |
References
- http://rhn.redhat.com/errata/RHSA-2014-1688.html
- http://rhn.redhat.com/errata/RHSA-2014-1789.html
- http://rhn.redhat.com/errata/RHSA-2014-1790.html
- http://www.openwall.com/lists/oss-security/2014/09/16/10
- http://www.ubuntu.com/usn/USN-2406-1
- https://bugs.launchpad.net/keystone/+bug/1354208
- http://rhn.redhat.com/errata/RHSA-2014-1688.html
- http://rhn.redhat.com/errata/RHSA-2014-1789.html
- http://rhn.redhat.com/errata/RHSA-2014-1790.html
- http://www.openwall.com/lists/oss-security/2014/09/16/10
- http://www.ubuntu.com/usn/USN-2406-1
- https://bugs.launchpad.net/keystone/+bug/1354208