CVE-2014-2237
published 2014-04-01CVE-2014-2237: The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.37%
69.0th percentile
The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2013.2.3-1 (bookworm) | keystone 2013.2.3-1 (bookworm) |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | >= 0 < 2013.2.3-1 | 2013.2.3-1 |
| openstack | keystone | >= 0 < 2013.2.3-1 | 2013.2.3-1 |
| openstack | keystone | >= 0 < 2013.2.3-1 | 2013.2.3-1 |
| openstack | keystone | >= 0 < 2013.2.3-1 | 2013.2.3-1 |
| openstack | keystone | >= 0 < 8.0.0a0 | 8.0.0a0 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend
ghsa·2022-05-17
CVE-2014-2237 [HIGH] CWE-1270 OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend
OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend
The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions.
OSV
OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend
osv·2022-05-17
CVE-2014-2237 [HIGH] OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend
OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend
The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions.
OSV
CVE-2014-2237: The memcache token backend in OpenStack Identity (Keystone) 2013
osv·2014-04-01·CVSS 5.0
CVE-2014-2237 [MEDIUM] CVE-2014-2237: The memcache token backend in OpenStack Identity (Keystone) 2013
The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions.
Debian
CVE-2014-2237: keystone - The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013...
vendor_debian·2014·CVSS 5.0
CVE-2014-2237 [MEDIUM] CVE-2014-2237: keystone - The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013...
The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions.
Scope: local
bookworm: resolved (fixed in 2013.2.3-1)
bullseye: resolved (fixed in 2013.2.3-1)
forky: resolved (fixed in 2013.2.3-1)
sid: resolved (fixed in 2013.2.3-1)
trixie: resolved (fixed in 2013.2.3-1)
Red Hat
openstack-keystone: trustee token revocation does not work with memcache backend
vendor_redhat·2013-12-11·CVSS 5.0
CVE-2014-2237 [MEDIUM] CWE-613 openstack-keystone: trustee token revocation does not work with memcache backend
openstack-keystone: trustee token revocation does not work with memcache backend
The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-2237 openstack-keystone: trustee token revocation does not work with memcache backend
bugzilla·2014-02-28·CVSS 5.0
CVE-2014-2237 [MEDIUM] CVE-2014-2237 openstack-keystone: trustee token revocation does not work with memcache backend
CVE-2014-2237 openstack-keystone: trustee token revocation does not work with memcache backend
Title: Trustee token revocation does not work with memcache backend
Reporter: Morgan Fainberg (Metacloud)
Products: Keystone
Versions: 2013.1 up to 2013.1.4 and 2013.2 versions up to 2013.2.2
Description:
Morgan Fainberg from Metacloud reported a vulnerability in the Keystone
memcache token backend. When a trustor issues a trust token with
impersonation enabled, the token is only added to the trustor's token
list and not to the trustee's token list. This results in the trust
token not being invalidated by the trustee's token revocation (bulk
revocation). This is most noticeable when the trustee user is disabled
or the trustee changes a password. Only setups using the memcache
backend for tokens
Bugzilla
CVE-2014-2237 openstack-keystone: trustee token revocation does not work with memcache backend [fedora-all]
bugzilla·2014-02-28·CVSS 5.0
CVE-2014-2237 [MEDIUM] CVE-2014-2237 openstack-keystone: trustee token revocation does not work with memcache backend [fedora-all]
CVE-2014-2237 openstack-keystone: trustee token revocation does not work with memcache backend [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available
http://rhn.redhat.com/errata/RHSA-2014-0580.htmlhttp://www.openwall.com/lists/oss-security/2014/03/04/16http://www.securityfocus.com/bid/65895https://bugs.launchpad.net/keystone/+bug/1260080http://rhn.redhat.com/errata/RHSA-2014-0580.htmlhttp://www.openwall.com/lists/oss-security/2014/03/04/16http://www.securityfocus.com/bid/65895https://bugs.launchpad.net/keystone/+bug/1260080
2014-04-01
Published