CVE-2014-3621
published 2014-10-02CVE-2014-3621: The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive…
PriorityP419medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
2.11%
79.7th percentile
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | keystone | < keystone 2014.1.3-1 (bookworm) | keystone 2014.1.3-1 (bookworm) |
| openstack | keystone | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| openstack | keystone | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| openstack | keystone | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| openstack | keystone | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| openstack | keystone | >= 0 < 8.0.0a0 | 8.0.0a0 |
| openstack | keystone | >= 2013.2 < 2013.2.3 | 2013.2.3 |
| openstack | keystone | >= 2014.1 < 2014.1.2.1 | 2014.1.2.1 |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Keystone vulnerability
vendor_ubuntu·2014-11-11
CVE-2014-3621 OpenStack Keystone vulnerability
Title: OpenStack Keystone vulnerability
Summary: OpenStack Keystone could be made to expose sensitive information over the
network.
Brant Knudson discovered that OpenStack Keystone did not properly perform
input sanitization when performing endpoint catalog substitution. A remote
attacker with privileged access for creating endpoints could exploit this
to obtain sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-keystone: configuration data information leak through Keystone catalog
vendor_redhat·2014-09-16·CVSS 4.0
CVE-2014-3621 [MEDIUM] CWE-200 openstack-keystone: configuration data information leak through Keystone catalog
openstack-keystone: configuration data information leak through Keystone catalog
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
A flaw was found in the keystone catalog URL replacement. A user with permissions to register an endpoint could use this flaw to leak configuration data, including the master admin_token. Only keystone setups that allow non-cloud-admin users to create endpoints were affected by this issue.
Debian
CVE-2014-3621: keystone - The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and...
vendor_debian·2014·CVSS 4.0
CVE-2014-3621 [MEDIUM] CVE-2014-3621: keystone - The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and...
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
Scope: local
bookworm: resolved (fixed in 2014.1.3-1)
bullseye: resolved (fixed in 2014.1.3-1)
forky: resolved (fixed in 2014.1.3-1)
sid: resolved (fixed in 2014.1.3-1)
trixie: resolved (fixed in 2014.1.3-1)
OSV
OpenStack Identity Keystone Exposure of Sensitive Information
osv·2022-05-13
CVE-2014-3621 [MEDIUM] OpenStack Identity Keystone Exposure of Sensitive Information
OpenStack Identity Keystone Exposure of Sensitive Information
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
GHSA
OpenStack Identity Keystone Exposure of Sensitive Information
ghsa·2022-05-13
CVE-2014-3621 [MEDIUM] CWE-200 OpenStack Identity Keystone Exposure of Sensitive Information
OpenStack Identity Keystone Exposure of Sensitive Information
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
OSV
CVE-2014-3621: The catalog url replacement in OpenStack Identity (Keystone) before 2013
osv·2014-10-02·CVSS 4.0
CVE-2014-3621 [MEDIUM] CVE-2014-3621: The catalog url replacement in OpenStack Identity (Keystone) before 2013
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3621 openstack-keystone: configuration data information leak through Keystone catalog [fedora-all]
bugzilla·2014-09-17·CVSS 4.0
CVE-2014-3621 [MEDIUM] CVE-2014-3621 openstack-keystone: configuration data information leak through Keystone catalog [fedora-all]
CVE-2014-3621 openstack-keystone: configuration data information leak through Keystone catalog [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2014-3621 openstack-keystone: configuration data information leak through Keystone catalog
bugzilla·2014-09-10·CVSS 4.0
CVE-2014-3621 [MEDIUM] CVE-2014-3621 openstack-keystone: configuration data information leak through Keystone catalog
CVE-2014-3621 openstack-keystone: configuration data information leak through Keystone catalog
The OpenStack project reports:
""
Title: Configuration option leak through Keystone catalog
Reporter: Brant Knudson (IBM)
Products: Keystone
Versions: up to 2013.2.3 and 2014.1 versions up to 2014.1.2.1
Description:
Brant Knudson from IBM reported a vulnerability in Keystone catalog URL
replacement. By creating a malicious endpoint a privileged user may
reveal configuration options resulting in sensitive information, like
master admin_token, being exposed through the service url. All Keystone
setups that allow non-admin users to create endpoints are affected.
""
Acknowledgements:
Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Brant Knudson f
http://rhn.redhat.com/errata/RHSA-2014-1688.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1789.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1790.htmlhttp://www.openwall.com/lists/oss-security/2014/09/16/10http://www.ubuntu.com/usn/USN-2406-1https://bugs.launchpad.net/keystone/+bug/1354208http://rhn.redhat.com/errata/RHSA-2014-1688.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1789.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1790.htmlhttp://www.openwall.com/lists/oss-security/2014/09/16/10http://www.ubuntu.com/usn/USN-2406-1https://bugs.launchpad.net/keystone/+bug/1354208
2014-10-02
Published