LWN.net Logo

keystone: multiple vulnerabilities

Package(s):keystone CVE #(s):CVE-2012-3542 CVE-2012-3426
Created:September 4, 2012 Updated:November 29, 2012
Description: From the Ubuntu advisory:

Dolph Mathews discovered that OpenStack Keystone did not properly restrict to administrative users the ability to update users' tenants. A remote attacker that can reach the administrative API can use this to add any user to any tenant. (CVE-2012-3542)

Derek Higgins discovered that OpenStack Keystone did not properly implement token expiration. A remote attacker could use this to continue to access an account that has been disabled or has a changed password. (CVE-2012-3426)

Alerts:
Ubuntu USN-1552-1 2012-09-03
Fedora FEDORA-2012-13075 2012-10-03
Red Hat RHSA-2012:1378-01 2012-10-16
Ubuntu USN-1641-1 2012-11-28

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds