CVE-2014-5251
published 2014-08-25CVE-2014-5251: The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which…
PriorityP424medium4.9CVSS 2.0
AVNACMAuSCPIPAN
EPSS
1.59%
73.0th percentile
The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | keystone | < keystone 2014.1.2.1-1 (bookworm) | keystone 2014.1.2.1-1 (bookworm) |
| glance_project | glance | >= 2011.2 < 2014.2.4 | 2014.2.4 |
| glance_project | glance | >= 2015.1.0 < 2015.1.2 | 2015.1.2 |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | >= 0 < 2014.1.2.1-1 | 2014.1.2.1-1 |
| openstack | keystone | >= 0 < 2014.1.2.1-1 | 2014.1.2.1-1 |
| openstack | keystone | >= 0 < 2014.1.2.1-1 | 2014.1.2.1-1 |
| openstack | keystone | >= 0 < 2014.1.2.1-1 | 2014.1.2.1-1 |
| openstack | keystone | >= 0 < 8.0.0a0 | 8.0.0a0 |
| openstack | keystone | >= 0 < 1:2014.1.2.1-0ubuntu1.1 | 1:2014.1.2.1-0ubuntu1.1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
osv6.0MEDIUM
vendor_ubuntu6.0MEDIUM
vendor_redhat5.5MEDIUM
vendor_debian4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Identity (Keystone) Multiple vulnerabilities in revocation events
ghsa·2022-05-17
CVE-2014-5251 [HIGH] CWE-613 OpenStack Identity (Keystone) Multiple vulnerabilities in revocation events
OpenStack Identity (Keystone) Multiple vulnerabilities in revocation events
The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.
OSV
OpenStack Identity (Keystone) Multiple vulnerabilities in revocation events
osv·2022-05-17
CVE-2014-5251 [HIGH] OpenStack Identity (Keystone) Multiple vulnerabilities in revocation events
OpenStack Identity (Keystone) Multiple vulnerabilities in revocation events
The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.
GHSA
OpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions
ghsa·2022-05-17
CVE-2015-5251 [MEDIUM] CWE-863 OpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions
OpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictions
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*.
OSV
CVE-2014-5251: The MySQL token driver in OpenStack Identity (Keystone) 2014
osv·2014-08-25·CVSS 4.9
CVE-2014-5251 [MEDIUM] CVE-2014-5251: The MySQL token driver in OpenStack Identity (Keystone) 2014
The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.
OSV
keystone vulnerabilities
osv·2014-08-21·CVSS 6.0
CVE-2014-3476 [MEDIUM] keystone vulnerabilities
keystone vulnerabilities
Steven Hardy discovered that OpenStack Keystone did not properly handle
chained delegation. A remove authenticated attacker could use this to
gain privileges by creating a new token with additional roles.
(CVE-2014-3476)
Jamie Lennox discovered that OpenStack Keystone did not properly validate
the project id. A remote authenticated attacker may be able to use this to
access other projects. (CVE-2014-3520)
Brant Knudson and Lance Bragstad discovered that OpenStack Keystone would
not always revoke tokens correctly. If Keystone were configured to use
revocation events, a remote authenticated attacker could continue to have
access to resources. (CVE-2014-5251, CVE-2014-5252, CVE-2014-5253)
Red Hat
openstack-glance allows illegal modification of image status
vendor_redhat·2015-09-22·CVSS 5.5
CVE-2015-5251 [MEDIUM] CWE-285 openstack-glance allows illegal modification of image status
openstack-glance allows illegal modification of image status
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*.
A flaw was discovered in the OpenStack Image service (glance) where a tenant could manipulate the status of their images by submitting an HTTP PUT request together with an 'x-image-meta-status' header. A malicious tenant could exploit this flaw to reactivate disabled images, bypass storage quotas, and in some cases replace image contents (where they have owner access). Setups using the Image service's v1 API could allow the illegal modification of image status. Additionally, setups whic
Ubuntu
OpenStack Keystone vulnerabilities
vendor_ubuntu·2014-08-21·CVSS 6.0
CVE-2014-3476 [MEDIUM] OpenStack Keystone vulnerabilities
Title: OpenStack Keystone vulnerabilities
Summary: Several security issues were fixed in OpenStack Keystone.
Steven Hardy discovered that OpenStack Keystone did not properly handle
chained delegation. A remove authenticated attacker could use this to
gain privileges by creating a new token with additional roles.
(CVE-2014-3476)
Jamie Lennox discovered that OpenStack Keystone did not properly validate
the project id. A remote authenticated attacker may be able to use this to
access other projects. (CVE-2014-3520)
Brant Knudson and Lance Bragstad discovered that OpenStack Keystone would
not always revoke tokens correctly. If Keystone were configured to use
revocation events, a remote authenticated attacker could continue to have
access to resources. (CVE-2014-5251, CVE-2014-5252, CVE-201
Red Hat
openstack-keystone: revocation events are broken with mysql
vendor_redhat·2014-07-23·CVSS 4.9
CVE-2014-5251 [MEDIUM] CWE-697 openstack-keystone: revocation events are broken with mysql
openstack-keystone: revocation events are broken with mysql
The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.
It was found that the MySQL token driver did not correctly store token expiration times, which prevented manual token revocation. Only OpenStack Identity setups configured to make use of revocation events were affected.
Statement: This issue does not affected openstack-keystone as shipped with Red Hat Enterprise Linux OpenStack Platform 4.0.
Package: openstack-keystone (Red Hat OpenStack Platform 4) - Not affected
Debian
CVE-2014-5251: keystone - The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2...
vendor_debian·2014·CVSS 4.9
CVE-2014-5251 [MEDIUM] CVE-2014-5251: keystone - The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2...
The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.
Scope: local
bookworm: resolved (fixed in 2014.1.2.1-1)
bullseye: resolved (fixed in 2014.1.2.1-1)
forky: resolved (fixed in 2014.1.2.1-1)
sid: resolved (fixed in 2014.1.2.1-1)
trixie: resolved (fixed in 2014.1.2.1-1)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2014-1121.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1122.htmlhttp://www.openwall.com/lists/oss-security/2014/08/15/6http://www.ubuntu.com/usn/USN-2324-1https://bugs.launchpad.net/keystone/+bug/1347961http://rhn.redhat.com/errata/RHSA-2014-1121.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1122.htmlhttp://www.openwall.com/lists/oss-security/2014/08/15/6http://www.ubuntu.com/usn/USN-2324-1https://bugs.launchpad.net/keystone/+bug/1347961
2014-08-25
Published