cbcvebase.
CVE-2014-3621
published 2014-10-02

CVE-2014-3621: The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive…

medium4CVSS 3.1
AVNACLAuSCPINAN
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.

Affected

11 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debiankeystone< keystone 2014.1.3-1 (bookworm)keystone 2014.1.3-1 (bookworm)
openstackkeystone>= 0 < 2014.1.3-12014.1.3-1
openstackkeystone>= 0 < 2014.1.3-12014.1.3-1
openstackkeystone>= 0 < 2014.1.3-12014.1.3-1
openstackkeystone>= 0 < 2014.1.3-12014.1.3-1
openstackkeystone>= 0 < 8.0.0a08.0.0a0
openstackkeystone>= 2013.2 < 2013.2.32013.2.3
openstackkeystone>= 2014.1 < 2014.1.2.12014.1.2.1
redhatopenstack
redhatopenstack

CVSS provenance

nvd4.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.0MEDIUM