CVE
CVE-2020-12692
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an OpenStack token an unlimited number of times.
- Severity
- MEDIUM
- CVSS
- 5.4
- Published
- Modified
Linked Releases
| Distribution | Release | Status | Evidence |
|---|---|---|---|
| Ubuntu | 18.04.6 amd64 desktop | unknown | source |
| Ubuntu | 18.04.6 amd64 live-server | unknown | source |
References
- http://www.openwall.com/lists/oss-security/2020/05/07/1
- https://bugs.launchpad.net/keystone/+bug/1872737
- https://security.openstack.org/ossa/OSSA-2020-003.html
- https://usn.ubuntu.com/4480-1/
- https://www.openwall.com/lists/oss-security/2020/05/06/4
- http://www.openwall.com/lists/oss-security/2020/05/07/1
- https://bugs.launchpad.net/keystone/+bug/1872737
- https://security.openstack.org/ossa/OSSA-2020-003.html
- https://usn.ubuntu.com/4480-1/
- https://www.openwall.com/lists/oss-security/2020/05/06/4