LWN.net Logo

openstack-keystone: insecure signing directory

Package(s):openstack-keystone CVE #(s):CVE-2013-2030
Created:May 22, 2013 Updated:June 27, 2013
Description: From the Openwall advisory:

Grant Murphy from Red Hat and Anton Lundin both independently reported a vulnerability in Nova's default location for the Keystone middleware signing directory (signing_dir). By previously setting up a malicious directory structure, an attacker with local shell access on the Nova node could potentially issue forged tokens that would be accepted by the middleware. Only setups that use the default value for signing_dir are affected. Note that future versions of the Keystone middleware will issue a warning if an insecure signing directory is used.

Alerts:
Fedora FEDORA-2013-8048 2013-05-22
openSUSE openSUSE-SU-2013:1087-1 2013-06-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds