CVE-2013-1865
published 2013-03-22CVE-2013-1865: OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote…
PriorityP338medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.61%
83.7th percentile
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | keystone | — | — |
| openstack | folsom | — | — |
| openstack | keystone | >= 2012.2 < 2012.2.4 | 2012.2.4 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Keystone vulnerability
vendor_ubuntu·2013-03-20
CVE-2013-1865 OpenStack Keystone vulnerability
Title: OpenStack Keystone vulnerability
Summary: Under certain configurations, Keystone would allow unintended access over
the network.
Guang Yee discovered that Keystone would not always perform all
verification checks when configured to use PKI. If the keystone server was
configured to use PKI and services or users requested online verification,
an attacker could potentially exploit this to bypass revocation checks.
Keystone uses UUID tokens by default in Ubuntu.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
keystone: online validation of Keystone PKI tokens bypasses revocation check
vendor_redhat·2013-03-20·CVSS 6.8
CVE-2013-1865 [MEDIUM] CWE-285 keystone: online validation of Keystone PKI tokens bypasses revocation check
keystone: online validation of Keystone PKI tokens bypasses revocation check
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.
Debian
CVE-2013-1865: keystone - OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks f...
vendor_debian·2013·CVSS 6.8
CVE-2013-1865 [MEDIUM] CVE-2013-1865: keystone - OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks f...
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
OpenStack Keystone Improper Authentication vulnerability
ghsa·2022-05-17
CVE-2013-1865 [MEDIUM] CWE-287 OpenStack Keystone Improper Authentication vulnerability
OpenStack Keystone Improper Authentication vulnerability
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.
OSV
OpenStack Keystone Improper Authentication vulnerability
osv·2022-05-17
CVE-2013-1865 [MEDIUM] OpenStack Keystone Improper Authentication vulnerability
OpenStack Keystone Improper Authentication vulnerability
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.
OSV
CVE-2013-1865: OpenStack Keystone Folsom (2012
osv·2013-03-22
CVE-2013-1865 CVE-2013-1865: OpenStack Keystone Folsom (2012
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1865 OpenStack keystone: online validation of Keystone PKI tokens bypasses revocation check [epel-6]
bugzilla·2013-03-27·CVSS 6.8
CVE-2013-1865 [MEDIUM] CVE-2013-1865 OpenStack keystone: online validation of Keystone PKI tokens bypasses revocation check [epel-6]
CVE-2013-1865 OpenStack keystone: online validation of Keystone PKI tokens bypasses revocation check [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when av
Bugzilla
CVE-2013-1865 OpenStack keystone: online validation of Keystone PKI tokens bypasses revocation check [fedora-18]
bugzilla·2013-03-20·CVSS 6.8
CVE-2013-1865 [MEDIUM] CVE-2013-1865 OpenStack keystone: online validation of Keystone PKI tokens bypasses revocation check [fedora-18]
CVE-2013-1865 OpenStack keystone: online validation of Keystone PKI tokens bypasses revocation check [fedora-18]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when avai
Bugzilla
CVE-2013-1865 OpenStack keystone: online validation of Keystone PKI tokens bypasses revocation check
bugzilla·2013-03-15·CVSS 6.8
CVE-2013-1865 [MEDIUM] CVE-2013-1865 OpenStack keystone: online validation of Keystone PKI tokens bypasses revocation check
CVE-2013-1865 OpenStack keystone: online validation of Keystone PKI tokens bypasses revocation check
Thierry Carrez ([email protected]) reports:
Title: Online validation of Keystone PKI tokens bypasses revocation check
Reporter: Guang Yee (HP)
Products: Keystone
Affects: Folsom
Description:
Guang Yee from HP reported a vulnerability in the revocation check for
Keystone PKI tokens. Those tokens are supposed to be validated locally
using cryptographic checks, but the user also has the option of asking
the server to validate them. In that case, the online verification of
PKI tokens would bypass the revocation check, potentially affirming
revocated tokens are still valid. Only setups making use of online
verification of PKI tokens are affected.
Proposed patches:
See attached patch. Unl
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101719.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00000.htmlhttp://osvdb.org/91532http://rhn.redhat.com/errata/RHSA-2013-0708.htmlhttp://secunia.com/advisories/52657http://www.openwall.com/lists/oss-security/2013/03/20/13http://www.securityfocus.com/bid/58616http://www.ubuntu.com/usn/USN-1772-1https://bugs.launchpad.net/keystone/+bug/1129713https://review.openstack.org/#/c/24906/http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101719.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00000.htmlhttp://osvdb.org/91532http://rhn.redhat.com/errata/RHSA-2013-0708.htmlhttp://secunia.com/advisories/52657http://www.openwall.com/lists/oss-security/2013/03/20/13http://www.securityfocus.com/bid/58616http://www.ubuntu.com/usn/USN-1772-1https://bugs.launchpad.net/keystone/+bug/1129713https://review.openstack.org/#/c/24906/
2013-03-22
Published