CVE-2014-0105
published 2014-04-15CVE-2014-0105: The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens…
PriorityP427medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
1.10%
62.3th percentile
The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2013.1.1-2 (bookworm) | keystone 2013.1.1-2 (bookworm) |
| debian | python-keystoneclient | < keystone 2013.1.1-2 (bookworm) | keystone 2013.1.1-2 (bookworm) |
| openstack | keystone | >= 0 < 2013.1.1-2 | 2013.1.1-2 |
| openstack | keystone | >= 0 < 2013.1.1-2 | 2013.1.1-2 |
| openstack | keystone | >= 0 < 2013.1.1-2 | 2013.1.1-2 |
| openstack | keystone | >= 0 < 2013.1.1-2 | 2013.1.1-2 |
| openstack | python-keystoneclient | <= 0.4.2 | — |
| openstack | python-keystoneclient | — | — |
| openstack | python-keystoneclient | — | — |
| openstack | python-keystoneclient | — | — |
| openstack | python-keystoneclient | — | — |
| openstack | python-keystoneclient | — | — |
| openstack | python-keystoneclient | — | — |
| openstack | python-keystoneclient | >= 0 < 1:0.6.0-4 | 1:0.6.0-4 |
| openstack | python-keystoneclient | >= 0 < 1:0.6.0-4 | 1:0.6.0-4 |
| openstack | python-keystoneclient | >= 0 < 1:0.6.0-4 | 1:0.6.0-4 |
| openstack | python-keystoneclient | >= 0 < 1:0.6.0-4 | 1:0.6.0-4 |
| openstack | python-keystoneclient | >= 0 < 0.7.0 | 0.7.0 |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
python-keystoneclient: Potential context confusion in Keystone middleware
vendor_redhat·2014-03-27·CVSS 6.0
CVE-2014-0105 [MEDIUM] python-keystoneclient: Potential context confusion in Keystone middleware
python-keystoneclient: Potential context confusion in Keystone middleware
The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."
Debian
CVE-2014-0105: keystone - The auth_token middleware in the OpenStack Python client library for Keystone (a...
vendor_debian·2014·CVSS 6.0
CVE-2014-0105 [MEDIUM] CVE-2014-0105: keystone - The auth_token middleware in the OpenStack Python client library for Keystone (a...
The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."
Scope: local
bookworm: resolved (fixed in 2013.1.1-2)
bullseye: resolved (fixed in 2013.1.1-2)
forky: resolved (fixed in 2013.1.1-2)
sid: resolved (fixed in 2013.1.1-2)
trixie: resolved (fixed in 2013.1.1-2)
OSV
python-keystoneclient vulnerable to context confusion in Keystone auth_token middleware
osv·2022-05-17
CVE-2014-0105 [LOW] python-keystoneclient vulnerable to context confusion in Keystone auth_token middleware
python-keystoneclient vulnerable to context confusion in Keystone auth_token middleware
A context confusion vulnerability was identified in Keystone auth_token middleware (shipped in python-keystoneclient) before 0.7.0. By doing repeated requests, with sufficient load on the target system, an authenticated user may in certain situations assume another authenticated user's complete identity and multi-tenant authorizations, potentially resulting in a privilege escalation. Note that it is related to a bad interaction between eventlet and python-memcached that should be avoided if the calling process already monkey-patches "thread" to use eventlet. Only keystone middleware setups using auth_token with memcache are vulnerable.
GHSA
python-keystoneclient vulnerable to context confusion in Keystone auth_token middleware
ghsa·2022-05-17
CVE-2014-0105 [LOW] CWE-522 python-keystoneclient vulnerable to context confusion in Keystone auth_token middleware
python-keystoneclient vulnerable to context confusion in Keystone auth_token middleware
A context confusion vulnerability was identified in Keystone auth_token middleware (shipped in python-keystoneclient) before 0.7.0. By doing repeated requests, with sufficient load on the target system, an authenticated user may in certain situations assume another authenticated user's complete identity and multi-tenant authorizations, potentially resulting in a privilege escalation. Note that it is related to a bad interaction between eventlet and python-memcached that should be avoided if the calling process already monkey-patches "thread" to use eventlet. Only keystone middleware setups using auth_token with memcache are vulnerable.
OSV
CVE-2014-0105: The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0
osv·2014-04-15·CVSS 6.0
CVE-2014-0105 [MEDIUM] CVE-2014-0105: The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0
The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0105 python-keystoneclient: Potential context confusion in Keystone middleware [fedora-all]
bugzilla·2014-03-28·CVSS 6.0
CVE-2014-0105 [MEDIUM] CVE-2014-0105 python-keystoneclient: Potential context confusion in Keystone middleware [fedora-all]
CVE-2014-0105 python-keystoneclient: Potential context confusion in Keystone middleware [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Plea
Bugzilla
CVE-2014-0105 python-keystoneclient: Potential context confusion in Keystone middleware
bugzilla·2014-03-28·CVSS 6.0
CVE-2014-0105 [MEDIUM] CVE-2014-0105 python-keystoneclient: Potential context confusion in Keystone middleware
CVE-2014-0105 python-keystoneclient: Potential context confusion in Keystone middleware
Kieran Spear from the University of Melbourne reported [1] a vulnerability
in Keystone auth_token middleware (shipped in python-keystoneclient). By
doing repeated requests, with sufficient load on the target system, an
authenticated user may in certain situations assume another
authenticated user's complete identity and multi-tenant authorizations,
potentially resulting in a privilege escalation. Note that it is related
to a bad interaction between eventlet and python-memcached that should
be avoided if the calling process already monkey-patches "thread" to use
eventlet. Only keystone middleware setups using auth_token with memcache
are vulnerable.
python-keystoneclient fix (included in 0.7.0 release)
Bugzilla
CVE-2014-0105 python-keystoneclient: Potential context confusion in Keystone middleware [epel-6]
bugzilla·2014-03-28·CVSS 6.0
CVE-2014-0105 [MEDIUM] CVE-2014-0105 python-keystoneclient: Potential context confusion in Keystone middleware [epel-6]
CVE-2014-0105 python-keystoneclient: Potential context confusion in Keystone middleware [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epe
http://rhn.redhat.com/errata/RHSA-2014-0382.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0409.htmlhttp://www.openwall.com/lists/oss-security/2014/03/27/4https://bugs.launchpad.net/python-keystoneclient/+bug/1282865http://rhn.redhat.com/errata/RHSA-2014-0382.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0409.htmlhttp://www.openwall.com/lists/oss-security/2014/03/27/4https://bugs.launchpad.net/python-keystoneclient/+bug/1282865
2014-04-15
Published