CVE-2014-3476
published 2014-06-17CVE-2014-3476: OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote…
PriorityP429medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
2.31%
81.4th percentile
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2014.1.1-2 (bookworm) | keystone 2014.1.1-2 (bookworm) |
| openstack | keystone | >= 0 < 2014.1.1-2 | 2014.1.1-2 |
| openstack | keystone | >= 0 < 2014.1.1-2 | 2014.1.1-2 |
| openstack | keystone | >= 0 < 2014.1.1-2 | 2014.1.1-2 |
| openstack | keystone | >= 0 < 2014.1.1-2 | 2014.1.1-2 |
| openstack | keystone | >= 0 < 8.0.0a0 | 8.0.0a0 |
| openstack | keystone | >= 0 < 1:2014.1.2.1-0ubuntu1.1 | 1:2014.1.2.1-0ubuntu1.1 |
| openstack | keystone | >= 2013.2 < 2013.2.4 | 2013.2.4 |
| openstack | keystone | >= 2014.1 < 2014.1.2 | 2014.1.2 |
| suse | cloud | — | — |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
vendor_ubuntu6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege
ghsa·2022-05-13
CVE-2014-3476 [MEDIUM] CWE-269 OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege
OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.
OSV
OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege
osv·2022-05-13
CVE-2014-3476 [MEDIUM] OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege
OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.
OSV
keystone vulnerabilities
osv·2014-08-21·CVSS 6.0
CVE-2014-3476 [MEDIUM] keystone vulnerabilities
keystone vulnerabilities
Steven Hardy discovered that OpenStack Keystone did not properly handle
chained delegation. A remove authenticated attacker could use this to
gain privileges by creating a new token with additional roles.
(CVE-2014-3476)
Jamie Lennox discovered that OpenStack Keystone did not properly validate
the project id. A remote authenticated attacker may be able to use this to
access other projects. (CVE-2014-3520)
Brant Knudson and Lance Bragstad discovered that OpenStack Keystone would
not always revoke tokens correctly. If Keystone were configured to use
revocation events, a remote authenticated attacker could continue to have
access to resources. (CVE-2014-5251, CVE-2014-5252, CVE-2014-5253)
OSV
CVE-2014-3476: OpenStack Identity (Keystone) before 2013
osv·2014-06-17·CVSS 6.0
CVE-2014-3476 [MEDIUM] CVE-2014-3476: OpenStack Identity (Keystone) before 2013
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.
Ubuntu
OpenStack Keystone vulnerabilities
vendor_ubuntu·2014-08-21·CVSS 6.0
CVE-2014-3476 [MEDIUM] OpenStack Keystone vulnerabilities
Title: OpenStack Keystone vulnerabilities
Summary: Several security issues were fixed in OpenStack Keystone.
Steven Hardy discovered that OpenStack Keystone did not properly handle
chained delegation. A remove authenticated attacker could use this to
gain privileges by creating a new token with additional roles.
(CVE-2014-3476)
Jamie Lennox discovered that OpenStack Keystone did not properly validate
the project id. A remote authenticated attacker may be able to use this to
access other projects. (CVE-2014-3520)
Brant Knudson and Lance Bragstad discovered that OpenStack Keystone would
not always revoke tokens correctly. If Keystone were configured to use
revocation events, a remote authenticated attacker could continue to have
access to resources. (CVE-2014-5251, CVE-2014-5252, CVE-201
Red Hat
openstack-keystone: privilege escalation through trust chained delegation
vendor_redhat·2014-06-12·CVSS 6.0
CVE-2014-3476 [MEDIUM] openstack-keystone: privilege escalation through trust chained delegation
openstack-keystone: privilege escalation through trust chained delegation
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.
A flaw was found in keystone's chained delegation. A trustee able to create a delegation from a trust or an OAuth token could misuse identity impersonation to bypass the enforced scope, possibly allowing them to obtain elevated privileges to the trustor's projects and roles.
Package: openstack-keystone (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Affected
Debian
CVE-2014-3476: keystone - OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno ...
vendor_debian·2014·CVSS 6.0
CVE-2014-3476 [MEDIUM] CVE-2014-3476: keystone - OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno ...
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.
Scope: local
bookworm: resolved (fixed in 2014.1.1-2)
bullseye: resolved (fixed in 2014.1.1-2)
forky: resolved (fixed in 2014.1.1-2)
sid: resolved (fixed in 2014.1.1-2)
trixie: resolved (fixed in 2014.1.1-2)
Suricata
ET MALWARE Bossabot DDoS tool RFI attempt
suricata·2014-09-22·CVSS 9.8
CVE-2012-1823 [CRITICAL] ET MALWARE Bossabot DDoS tool RFI attempt
ET MALWARE Bossabot DDoS tool RFI attempt
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET MALWARE Bossabot DDoS tool RFI attempt"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"php?-d|20|allow_url"; fast_pattern; content:"auto_prepend_file|3d|php|3a 2f|"; http.request_body; content:"<?php|0d 0a|"; startswith; reference:url,www.kernelmode.info/forum/viewtopic.php?f=16&t=3476&p=23965#p23965; reference:url,cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1823; classtype:trojan-activity; sid:2019212; rev:5; metadata:created_at 2014_09_22, signature_severity Major, tag CISA_KEV, updated_at 2024_04_13;)
No public exploits indexed.
Bugzilla
CVE-2014-3476 openstack-keystone: privilege escalation through trust chained delegation [epel-6]
bugzilla·2014-06-13·CVSS 6.0
CVE-2014-3476 [MEDIUM] CVE-2014-3476 openstack-keystone: privilege escalation through trust chained delegation [epel-6]
CVE-2014-3476 openstack-keystone: privilege escalation through trust chained delegation [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tra
Bugzilla
CVE-2014-3476 openstack-keystone: privilege escalation through trust chained delegation [fedora-all]
bugzilla·2014-06-13·CVSS 6.0
CVE-2014-3476 [MEDIUM] CVE-2014-3476 openstack-keystone: privilege escalation through trust chained delegation [fedora-all]
CVE-2014-3476 openstack-keystone: privilege escalation through trust chained delegation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this
Bugzilla
CVE-2014-3476 openstack-keystone: privilege escalation through trust chained delegation
bugzilla·2014-06-04·CVSS 6.0
CVE-2014-3476 [MEDIUM] CVE-2014-3476 openstack-keystone: privilege escalation through trust chained delegation
CVE-2014-3476 openstack-keystone: privilege escalation through trust chained delegation
Openstack VMT reports:
Title: Keystone privilege escalation through trust chained delegation
Reporter: Steven Hardy (Red Hat)
Products: Keystone
Versions: up to 2013.2.3, and 2014.1 to 2014.1.1
Description:
Steven Hardy from Red Hat reported a vulnerability in Keystone chained delegation.
By creating a delegation from a trust or OAuth token, a trustee may abuse the identity impersonation against keystone and circumvent the enforced scope, resulting in potential elevated privileges to any of the trustor's projects and or roles. All Keystone deployments configured to enable trusts are affected, which has been the default since Grizzly.
Discussion:
Acknowledgements:
This issue was discovered by Steve
http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00031.htmlhttp://secunia.com/advisories/57886http://secunia.com/advisories/59547http://www.openwall.com/lists/oss-security/2014/06/12/3http://www.securityfocus.com/bid/68026https://bugs.launchpad.net/keystone/+bug/1324592http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00031.htmlhttp://secunia.com/advisories/57886http://secunia.com/advisories/59547http://www.openwall.com/lists/oss-security/2014/06/12/3http://www.securityfocus.com/bid/68026https://bugs.launchpad.net/keystone/+bug/1324592
2014-06-17
Published