cbcvebase.
CVE-2014-3621
published 2014-10-02

CVE-2014-3621: The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive…

PriorityP419medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
2.11%
79.7th percentile
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.

Affected

11 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debiankeystone< keystone 2014.1.3-1 (bookworm)keystone 2014.1.3-1 (bookworm)
openstackkeystone>= 0 < 2014.1.3-12014.1.3-1
openstackkeystone>= 0 < 2014.1.3-12014.1.3-1
openstackkeystone>= 0 < 2014.1.3-12014.1.3-1
openstackkeystone>= 0 < 2014.1.3-12014.1.3-1
openstackkeystone>= 0 < 8.0.0a08.0.0a0
openstackkeystone>= 2013.2 < 2013.2.32013.2.3
openstackkeystone>= 2014.1 < 2014.1.2.12014.1.2.1
redhatopenstack
redhatopenstack

CVSS provenance

nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.