Search CVE reports


Toggle filters

11 – 20 of 57 results


CVE-2017-2673

Medium priority

Some fixes available 1 of 3

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted...

1 affected package

keystone

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone
Show less packages

CVE-2016-4911

Medium priority
Ignored

The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.

1 affected package

keystone

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone
Show less packages

CVE-2015-7546

Medium priority
Ignored

The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly...

2 affected packages

keystone, python-keystonemiddleware

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone
python-keystonemiddleware
Show less packages

CVE-2015-3646

Medium priority
Ignored

OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information...

1 affected package

keystone

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone
Show less packages

CVE-2015-1852

Medium priority

Some fixes available 3 of 5

The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless...

2 affected packages

python-keystoneclient, python-keystonemiddleware

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-keystoneclient
python-keystonemiddleware
Show less packages

CVE-2014-7144

Medium priority

Some fixes available 1 of 3

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the...

2 affected packages

python-keystoneclient, python-keystonemiddleware

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-keystoneclient
python-keystonemiddleware
Show less packages

CVE-2014-5253

Medium priority
Fixed

OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for...

1 affected package

keystone

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone
Show less packages

CVE-2014-5252

Medium priority
Fixed

The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access...

1 affected package

keystone

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone
Show less packages

CVE-2014-5251

Medium priority
Fixed

The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote...

1 affected package

keystone

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone
Show less packages

CVE-2014-3621

Medium priority

Some fixes available 7 of 8

The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by...

1 affected package

keystone

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone
Show less packages