CVE-2013-6391
published 2013-12-14CVE-2013-6391: The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is…
PriorityP434medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
2.24%
80.8th percentile
The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | keystone | < keystone 2013.2.1-1 (bookworm) | keystone 2013.2.1-1 (bookworm) |
| openstack | keystone | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | keystone | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | keystone | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | keystone | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | keystone | >= 2013.2 < 2013.2.1 | 2013.2.1 |
| redhat | openstack | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3fpm-8w39-5p69: The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013
ghsa_unreviewed·2022-05-13
CVE-2013-6391 [MEDIUM] CWE-269 GHSA-3fpm-8w39-5p69: The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013
The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.
OSV
CVE-2013-6391: The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013
osv·2013-12-14·CVSS 5.8
CVE-2013-6391 [MEDIUM] CVE-2013-6391: The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013
The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.
Ubuntu
OpenStack Keystone vulnerability
vendor_ubuntu·2013-12-19
CVE-2013-6391 OpenStack Keystone vulnerability
Title: OpenStack Keystone vulnerability
Summary: Keystone access controls could be circumvented via EC2-style tokens.
Steven Hardy discovered that Keystone did not properly enforce trusts when
using the ec2tokens API. An authenticated attacker could exploit this to
retrieve a token not scoped to the trust and elevate privileges to the
trustor's roles.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Keystone: trust circumvention through EC2-style tokens
vendor_redhat·2013-12-11·CVSS 5.8
CVE-2013-6391 [MEDIUM] Keystone: trust circumvention through EC2-style tokens
Keystone: trust circumvention through EC2-style tokens
The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.
Debian
CVE-2013-6391: keystone - The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Ic...
vendor_debian·2013·CVSS 5.8
CVE-2013-6391 [MEDIUM] CVE-2013-6391: keystone - The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Ic...
The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.
Scope: local
bookworm: resolved (fixed in 2013.2.1-1)
bullseye: resolved (fixed in 2013.2.1-1)
forky: resolved (fixed in 2013.2.1-1)
sid: resolved (fixed in 2013.2.1-1)
trixie: resolved (fixed in 2013.2.1-1)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2014-0089.htmlhttp://secunia.com/advisories/56079http://secunia.com/advisories/56154http://www.openwall.com/lists/oss-security/2013/12/11/7http://www.securityfocus.com/bid/64253http://www.ubuntu.com/usn/USN-2061-1https://bugs.launchpad.net/keystone/+bug/1242597https://exchange.xforce.ibmcloud.com/vulnerabilities/89657http://rhn.redhat.com/errata/RHSA-2014-0089.htmlhttp://secunia.com/advisories/56079http://secunia.com/advisories/56154http://www.openwall.com/lists/oss-security/2013/12/11/7http://www.securityfocus.com/bid/64253http://www.ubuntu.com/usn/USN-2061-1https://bugs.launchpad.net/keystone/+bug/1242597https://exchange.xforce.ibmcloud.com/vulnerabilities/89657
2013-12-14
Published