CVE-2014-3520
published 2014-10-26CVE-2014-3520: OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to an…
PriorityP434medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.91%
77.4th percentile
OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to an unauthorized project for which the trustor has certain roles via the project ID in a V2 API trust token request.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2014.1.1-3 (bookworm) | keystone 2014.1.1-3 (bookworm) |
| openstack | keystone | >= 0 < 2014.1.1-3 | 2014.1.1-3 |
| openstack | keystone | >= 0 < 2014.1.1-3 | 2014.1.1-3 |
| openstack | keystone | >= 0 < 2014.1.1-3 | 2014.1.1-3 |
| openstack | keystone | >= 0 < 2014.1.1-3 | 2014.1.1-3 |
| openstack | keystone | >= 0 < 1:2014.1.2.1-0ubuntu1.1 | 1:2014.1.2.1-0ubuntu1.1 |
| openstack | keystone | >= 2013.2 < 2013.2.4 | 2013.2.4 |
| openstack | keystone | >= 2014.1 < 2014.1.2 | 2014.1.2 |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Keystone vulnerabilities
vendor_ubuntu·2014-08-21·CVSS 6.0
CVE-2014-3476 [MEDIUM] OpenStack Keystone vulnerabilities
Title: OpenStack Keystone vulnerabilities
Summary: Several security issues were fixed in OpenStack Keystone.
Steven Hardy discovered that OpenStack Keystone did not properly handle
chained delegation. A remove authenticated attacker could use this to
gain privileges by creating a new token with additional roles.
(CVE-2014-3476)
Jamie Lennox discovered that OpenStack Keystone did not properly validate
the project id. A remote authenticated attacker may be able to use this to
access other projects. (CVE-2014-3520)
Brant Knudson and Lance Bragstad discovered that OpenStack Keystone would
not always revoke tokens correctly. If Keystone were configured to use
revocation events, a remote authenticated attacker could continue to have
access to resources. (CVE-2014-5251, CVE-2014-5252, CVE-201
Red Hat
openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id
vendor_redhat·2014-07-02·CVSS 6.5
CVE-2014-3520 [MEDIUM] CWE-863 openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id
openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id
OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to an unauthorized project for which the trustor has certain roles via the project ID in a V2 API trust token request.
A flaw was found in the way keystone handled trusts. A trustee could use an out-of-scope project ID to gain unauthorized access to a project if the trustor had the required roles for that requested project.
Package: openstack-keystone (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Affected
Debian
CVE-2014-3520: keystone - OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno ...
vendor_debian·2014·CVSS 6.5
CVE-2014-3520 [MEDIUM] CVE-2014-3520: keystone - OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno ...
OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to an unauthorized project for which the trustor has certain roles via the project ID in a V2 API trust token request.
Scope: local
bookworm: resolved (fixed in 2014.1.1-3)
bullseye: resolved (fixed in 2014.1.1-3)
forky: resolved (fixed in 2014.1.1-3)
sid: resolved (fixed in 2014.1.1-3)
trixie: resolved (fixed in 2014.1.1-3)
GHSA
GHSA-mv96-4gm9-mjhw: OpenStack Identity (Keystone) before 2013
ghsa_unreviewed·2022-05-13
CVE-2014-3520 [MEDIUM] CWE-863 GHSA-mv96-4gm9-mjhw: OpenStack Identity (Keystone) before 2013
OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to an unauthorized project for which the trustor has certain roles via the project ID in a V2 API trust token request.
OSV
CVE-2014-3520: OpenStack Identity (Keystone) before 2013
osv·2014-10-26·CVSS 6.5
CVE-2014-3520 [MEDIUM] CVE-2014-3520: OpenStack Identity (Keystone) before 2013
OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to an unauthorized project for which the trustor has certain roles via the project ID in a V2 API trust token request.
OSV
keystone vulnerabilities
osv·2014-08-21·CVSS 6.0
CVE-2014-3476 [MEDIUM] keystone vulnerabilities
keystone vulnerabilities
Steven Hardy discovered that OpenStack Keystone did not properly handle
chained delegation. A remove authenticated attacker could use this to
gain privileges by creating a new token with additional roles.
(CVE-2014-3476)
Jamie Lennox discovered that OpenStack Keystone did not properly validate
the project id. A remote authenticated attacker may be able to use this to
access other projects. (CVE-2014-3520)
Brant Knudson and Lance Bragstad discovered that OpenStack Keystone would
not always revoke tokens correctly. If Keystone were configured to use
revocation events, a remote authenticated attacker could continue to have
access to resources. (CVE-2014-5251, CVE-2014-5252, CVE-2014-5253)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3520 openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id [epel-6]
bugzilla·2014-07-02·CVSS 6.5
CVE-2014-3520 [MEDIUM] CVE-2014-3520 openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id [epel-6]
CVE-2014-3520 openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when ava
Bugzilla
CVE-2014-3520 openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id [fedora-20]
bugzilla·2014-07-02·CVSS 6.5
CVE-2014-3520 [MEDIUM] CVE-2014-3520 openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id [fedora-20]
CVE-2014-3520 openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id [fedora-20]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when avail
Bugzilla
CVE-2014-3520 openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id [fedora-19]
bugzilla·2014-07-02·CVSS 6.5
CVE-2014-3520 [MEDIUM] CVE-2014-3520 openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id [fedora-19]
CVE-2014-3520 openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id [fedora-19]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when avail
Bugzilla
CVE-2014-3520 openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id
bugzilla·2014-06-24·CVSS 6.5
CVE-2014-3520 [MEDIUM] CVE-2014-3520 openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id
CVE-2014-3520 openstack-keystone: Keystone V2 trusts privilege escalation through user supplied project id
The OpenStack project reports:
...
Title: Keystone V2 trusts privilege escalation through user supplied project id
Reporter: Jamie Lennox (Red Hat)
Products: Keystone
Versions: up to 2013.2.3, and 2014.1 to 2014.1.1
Description:
Jamie Lennox from Red Hat reported a vulnerability in Keystone trusts.
By using an out of scope project id, a trustee may gain unauthorized
access if the trustor has the required roles in the requested project
id. All Keystone deployments configured to enable trusts and V2 API are
affected.
...
Acknowledgements:
Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Jamie Lennox from Red Hat as the original repor
http://lists.openstack.org/pipermail/openstack-announce/2014-July/000248.htmlhttp://secunia.com/advisories/59426https://bugs.launchpad.net/keystone/+bug/1331912http://lists.openstack.org/pipermail/openstack-announce/2014-July/000248.htmlhttp://secunia.com/advisories/59426https://bugs.launchpad.net/keystone/+bug/1331912
2014-10-26
Published