CVE-2014-5252
published 2014-08-25CVE-2014-5252: The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows…
PriorityP426medium4.9CVSS 2.0
AVNACMAuSCPIPAN
EPSS
1.52%
71.9th percentile
The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a verification (1) GET or (2) HEAD request to v3/auth/tokens/.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | keystone | < keystone 2014.1.2.1-1 (bookworm) | keystone 2014.1.2.1-1 (bookworm) |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | >= 0 < 2014.1.2.1-1 | 2014.1.2.1-1 |
| openstack | keystone | >= 0 < 2014.1.2.1-1 | 2014.1.2.1-1 |
| openstack | keystone | >= 0 < 2014.1.2.1-1 | 2014.1.2.1-1 |
| openstack | keystone | >= 0 < 2014.1.2.1-1 | 2014.1.2.1-1 |
| openstack | keystone | >= 0 < 8.0.0a0 | 8.0.0a0 |
| openstack | keystone | >= 0 < 1:2014.1.2.1-0ubuntu1.1 | 1:2014.1.2.1-0ubuntu1.1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
osv6.0MEDIUM
vendor_ubuntu6.0MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Identity (Keystone) UUID v2 tokens does not expire with revocation events
ghsa·2022-05-17
CVE-2014-5252 [HIGH] CWE-613 OpenStack Identity (Keystone) UUID v2 tokens does not expire with revocation events
OpenStack Identity (Keystone) UUID v2 tokens does not expire with revocation events
The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a verification (1) GET or (2) HEAD request to v3/auth/tokens/.
OSV
OpenStack Identity (Keystone) UUID v2 tokens does not expire with revocation events
osv·2022-05-17
CVE-2014-5252 [HIGH] OpenStack Identity (Keystone) UUID v2 tokens does not expire with revocation events
OpenStack Identity (Keystone) UUID v2 tokens does not expire with revocation events
The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a verification (1) GET or (2) HEAD request to v3/auth/tokens/.
OSV
CVE-2014-5252: The V3 API in OpenStack Identity (Keystone) 2014
osv·2014-08-25·CVSS 4.9
CVE-2014-5252 [MEDIUM] CVE-2014-5252: The V3 API in OpenStack Identity (Keystone) 2014
The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a verification (1) GET or (2) HEAD request to v3/auth/tokens/.
OSV
keystone vulnerabilities
osv·2014-08-21·CVSS 6.0
CVE-2014-3476 [MEDIUM] keystone vulnerabilities
keystone vulnerabilities
Steven Hardy discovered that OpenStack Keystone did not properly handle
chained delegation. A remove authenticated attacker could use this to
gain privileges by creating a new token with additional roles.
(CVE-2014-3476)
Jamie Lennox discovered that OpenStack Keystone did not properly validate
the project id. A remote authenticated attacker may be able to use this to
access other projects. (CVE-2014-3520)
Brant Knudson and Lance Bragstad discovered that OpenStack Keystone would
not always revoke tokens correctly. If Keystone were configured to use
revocation events, a remote authenticated attacker could continue to have
access to resources. (CVE-2014-5251, CVE-2014-5252, CVE-2014-5253)
Ubuntu
OpenStack Keystone vulnerabilities
vendor_ubuntu·2014-08-21·CVSS 6.0
CVE-2014-3476 [MEDIUM] OpenStack Keystone vulnerabilities
Title: OpenStack Keystone vulnerabilities
Summary: Several security issues were fixed in OpenStack Keystone.
Steven Hardy discovered that OpenStack Keystone did not properly handle
chained delegation. A remove authenticated attacker could use this to
gain privileges by creating a new token with additional roles.
(CVE-2014-3476)
Jamie Lennox discovered that OpenStack Keystone did not properly validate
the project id. A remote authenticated attacker may be able to use this to
access other projects. (CVE-2014-3520)
Brant Knudson and Lance Bragstad discovered that OpenStack Keystone would
not always revoke tokens correctly. If Keystone were configured to use
revocation events, a remote authenticated attacker could continue to have
access to resources. (CVE-2014-5251, CVE-2014-5252, CVE-201
Red Hat
openstack-keystone: token expiration date stored incorrectly
vendor_redhat·2014-07-25·CVSS 4.9
CVE-2014-5252 [MEDIUM] CWE-697 openstack-keystone: token expiration date stored incorrectly
openstack-keystone: token expiration date stored incorrectly
The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a verification (1) GET or (2) HEAD request to v3/auth/tokens/.
A flaw was found in keystone revocation events that resulted in the "issued_at" time being updated when a token created by the V2 API was processed by the V3 API. This could allow a user to evade token revocation. Only OpenStack Identity setups configured to make use of revocation events and UUID tokens were affected.
Statement: This issue does not affected openstack-keystone as shipped with Red Hat Enterprise Linux OpenStack Platform
Debian
CVE-2014-5252: keystone - The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno ...
vendor_debian·2014·CVSS 4.9
CVE-2014-5252 [MEDIUM] CVE-2014-5252: keystone - The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno ...
The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a verification (1) GET or (2) HEAD request to v3/auth/tokens/.
Scope: local
bookworm: resolved (fixed in 2014.1.2.1-1)
bullseye: resolved (fixed in 2014.1.2.1-1)
forky: resolved (fixed in 2014.1.2.1-1)
sid: resolved (fixed in 2014.1.2.1-1)
trixie: resolved (fixed in 2014.1.2.1-1)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2014-1121.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1122.htmlhttp://www.openwall.com/lists/oss-security/2014/08/15/6http://www.ubuntu.com/usn/USN-2324-1https://bugs.launchpad.net/keystone/+bug/1348820http://rhn.redhat.com/errata/RHSA-2014-1121.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1122.htmlhttp://www.openwall.com/lists/oss-security/2014/08/15/6http://www.ubuntu.com/usn/USN-2324-1https://bugs.launchpad.net/keystone/+bug/1348820
2014-08-25
Published