Search CVE reports


Toggle filters

21 – 30 of 57 results


CVE-2014-3520

Medium priority

Some fixes available 1 of 2

OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to an unauthorized project for which the trustor has certain roles via the project...

1 affected package

keystone

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone
Show less packages

CVE-2014-3476

Medium priority

Some fixes available 1 of 2

OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2)...

1 affected package

keystone

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone
Show less packages

CVE-2014-2828

Medium priority
Ignored

The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a...

1 affected package

keystone

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone
Show less packages

CVE-2014-2237

Low priority
Ignored

The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in...

1 affected package

keystone

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone
Show less packages

CVE-2014-0204

Medium priority
Not affected

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with...

1 affected package

keystone

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone
Show less packages

CVE-2014-0105

Low priority
Ignored

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain...

2 affected packages

keystone, python-keystoneclient

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone
python-keystoneclient
Show less packages

CVE-2013-6491

Medium priority

Some fixes available 3 of 4

The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.

5 affected packages

cinder, keystone, neutron, nova, quantum

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cinder
keystone
neutron
nova
quantum
Show less packages

CVE-2013-6391

Medium priority

Some fixes available 1 of 2

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating...

1 affected package

keystone

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone
Show less packages

CVE-2013-4477

Medium priority
Fixed

The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.

1 affected package

keystone

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone
Show less packages

CVE-2013-4294

Medium priority
Fixed

The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass...

1 affected package

keystone

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone
Show less packages