cbcvebase.
CVE-2014-0105
published 2014-04-15

CVE-2014-0105: The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens…

medium6CVSS 3.1
AVNACMAuSCPIPAP
The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."

Affected

18 ranges
VendorProductVersion rangeFixed in
debiankeystone< keystone 2013.1.1-2 (bookworm)keystone 2013.1.1-2 (bookworm)
debianpython-keystoneclient< keystone 2013.1.1-2 (bookworm)keystone 2013.1.1-2 (bookworm)
openstackkeystone>= 0 < 2013.1.1-22013.1.1-2
openstackkeystone>= 0 < 2013.1.1-22013.1.1-2
openstackkeystone>= 0 < 2013.1.1-22013.1.1-2
openstackkeystone>= 0 < 2013.1.1-22013.1.1-2
openstackpython-keystoneclient<= 0.4.2
openstackpython-keystoneclient
openstackpython-keystoneclient
openstackpython-keystoneclient
openstackpython-keystoneclient
openstackpython-keystoneclient
openstackpython-keystoneclient
openstackpython-keystoneclient>= 0 < 1:0.6.0-41:0.6.0-4
openstackpython-keystoneclient>= 0 < 1:0.6.0-41:0.6.0-4
openstackpython-keystoneclient>= 0 < 1:0.6.0-41:0.6.0-4
openstackpython-keystoneclient>= 0 < 1:0.6.0-41:0.6.0-4
openstackpython-keystoneclient>= 0 < 0.7.00.7.0

CVSS provenance

nvd6.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM