CVE-2014-7144
published 2014-10-02CVE-2014-7144: OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure"…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.96%
78.3th percentile
OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | python-keystoneclient | < python-keystoneclient 1:1.3.0-2 (bookworm) | python-keystoneclient 1:1.3.0-2 (bookworm) |
| debian | python-keystoneclient | < python-keystoneclient 1:0.10.1-2 (bookworm) | python-keystoneclient 1:0.10.1-2 (bookworm) |
| debian | python-keystonemiddleware | < python-keystoneclient 1:1.3.0-2 (bookworm) | python-keystoneclient 1:1.3.0-2 (bookworm) |
| debian | python-keystonemiddleware | < python-keystoneclient 1:0.10.1-2 (bookworm) | python-keystoneclient 1:0.10.1-2 (bookworm) |
| openstack | keystonemiddleware | <= 1.5.0 | — |
| openstack | keystonemiddleware | — | — |
| openstack | keystonemiddleware | — | — |
| openstack | keystonemiddleware | — | — |
| openstack | keystonemiddleware | >= 0 < 0.11.0 | 0.11.0 |
| openstack | keystonemiddleware | >= 0 < 1.6.0 | 1.6.0 |
| openstack | keystonemiddleware | >= 1.0 < 1.2.0 | 1.2.0 |
| openstack | python-keystoneclient | <= 0.10.1 | — |
| openstack | python-keystoneclient | <= 1.3.0 | — |
| openstack | python-keystoneclient | >= 0 < 1:1.3.0-2 | 1:1.3.0-2 |
| openstack | python-keystoneclient | >= 0 < 1:0.10.1-2 | 1:0.10.1-2 |
| openstack | python-keystoneclient | >= 0 < 1:1.3.0-2 | 1:1.3.0-2 |
| openstack | python-keystoneclient | >= 0 < 1:0.10.1-2 | 1:0.10.1-2 |
| openstack | python-keystoneclient | >= 0 < 1:1.3.0-2 | 1:1.3.0-2 |
| openstack | python-keystoneclient | >= 0 < 1:0.10.1-2 | 1:0.10.1-2 |
| openstack | python-keystoneclient | >= 0 < 1:1.3.0-2 | 1:1.3.0-2 |
| openstack | python-keystoneclient | >= 0 < 1:0.10.1-2 | 1:0.10.1-2 |
| openstack | python-keystoneclient | >= 0 < 0.11.0 | 0.11.0 |
| openstack | python-keystoneclient | >= 0 < 1.4.0 | 1.4.0 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa4.3MEDIUM
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack keystonemiddleware does not verify certificate
ghsa·2022-05-17
CVE-2014-7144 [HIGH] CWE-295 OpenStack keystonemiddleware does not verify certificate
OpenStack keystonemiddleware does not verify certificate
OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (`paste.ini`) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.
OSV
OpenStack keystonemiddleware does not verify certificate
osv·2022-05-17
CVE-2014-7144 [HIGH] OpenStack keystonemiddleware does not verify certificate
OpenStack keystonemiddleware does not verify certificate
OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (`paste.ini`) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.
GHSA
OpenStack keystonemiddleware and python-keystoneclient vulnerable to man-in-the-middle attacks
ghsa·2022-05-17·CVSS 4.3
CVE-2015-1852 [MEDIUM] CWE-295 OpenStack keystonemiddleware and python-keystoneclient vulnerable to man-in-the-middle attacks
OpenStack keystonemiddleware and python-keystoneclient vulnerable to man-in-the-middle attacks
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.
OSV
OpenStack keystonemiddleware and python-keystoneclient vulnerable to man-in-the-middle attacks
osv·2022-05-17·CVSS 4.3
CVE-2015-1852 [MEDIUM] OpenStack keystonemiddleware and python-keystoneclient vulnerable to man-in-the-middle attacks
OpenStack keystonemiddleware and python-keystoneclient vulnerable to man-in-the-middle attacks
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.
OSV
python-keystoneclient, python-keystonemiddleware vulnerabilities
osv·2015-08-06·CVSS 4.3
CVE-2014-7144 [MEDIUM] python-keystoneclient, python-keystonemiddleware vulnerabilities
python-keystoneclient, python-keystonemiddleware vulnerabilities
Qin Zhao discovered Keystone disabled certification verification when
the "insecure" option is set in a paste configuration (paste.ini)
file regardless of the value, which allows remote attackers to conduct
machine-in-the-middle attacks via a crafted certificate. (CVE-2014-7144)
Brant Knudson discovered Keystone disabled certification verification when
the "insecure" option is set in a paste configuration (paste.ini)
file regardless of the value, which allows remote attackers to conduct
machine-in-the-middle attacks via a crafted certificate. (CVE-2015-1852)
OSV
CVE-2015-1852: The s3_token middleware in OpenStack keystonemiddleware before 1
osv·2015-04-17·CVSS 4.3
CVE-2015-1852 [MEDIUM] CVE-2015-1852: The s3_token middleware in OpenStack keystonemiddleware before 1
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.
OSV
CVE-2014-7144: OpenStack keystonemiddleware (formerly python-keystoneclient) 0
osv·2014-10-02·CVSS 4.3
CVE-2014-7144 [MEDIUM] CVE-2014-7144: OpenStack keystonemiddleware (formerly python-keystoneclient) 0
OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.
Ubuntu
Keystone vulnerabilities
vendor_ubuntu·2015-08-06·CVSS 4.3
CVE-2014-7144 [MEDIUM] Keystone vulnerabilities
Title: Keystone vulnerabilities
Summary: Keystone could be made to expose sensitive information over the
network.
Qin Zhao discovered Keystone disabled certification verification when
the "insecure" option is set in a paste configuration (paste.ini)
file regardless of the value, which allows remote attackers to conduct
machine-in-the-middle attacks via a crafted certificate. (CVE-2014-7144)
Brant Knudson discovered Keystone disabled certification verification when
the "insecure" option is set in a paste configuration (paste.ini)
file regardless of the value, which allows remote attackers to conduct
machine-in-the-middle attacks via a crafted certificate. (CVE-2015-1852)
Instructions: After a standard system update you need to restart Keystone to make
all the necessary changes.
Red Hat
keystonemiddleware/keystoneclient: S3Token TLS cert verification option not honored
vendor_redhat·2015-04-15·CVSS 4.3
CVE-2015-1852 [MEDIUM] CWE-295 keystonemiddleware/keystoneclient: S3Token TLS cert verification option not honored
keystonemiddleware/keystoneclient: S3Token TLS cert verification option not honored
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.
It was discovered that some items in the S3Token paste configuration as used by python-keystonemiddleware (formerly python-keystoneclient) were incorrectly evaluated as strings, an issue similar to CVE-2014-7144. If the "insecure" option were set to "false", the option would be evaluated as true, resulting in TLS connections be
Debian
CVE-2015-1852: python-keystoneclient - The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-...
vendor_debian·2015·CVSS 4.3
CVE-2015-1852 [MEDIUM] CVE-2015-1852: python-keystoneclient - The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-...
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.
Scope: local
bookworm: resolved (fixed in 1:1.3.0-2)
bullseye: resolved (fixed in 1:1.3.0-2)
forky: resolved (fixed in 1:1.3.0-2)
sid: resolved (fixed in 1:1.3.0-2)
trixie: resolved (fixed in 1:1.3.0-2)
Red Hat
python-keystoneclient: TLS certificate verification disabled
vendor_redhat·2014-08-06·CVSS 4.3
CVE-2014-7144 [MEDIUM] CWE-295 python-keystoneclient: TLS certificate verification disabled
python-keystoneclient: TLS certificate verification disabled
OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.
It was found that python-keystoneclient treated all settings in paste.ini files as string types. If the "insecure" option were set to any value in a paste.ini configuration file, it would be evaluated as true, resulting in TLS connections being vulnerable to man-in-the-middle attacks.
Package: python-keystoneclient (Red Hat Storage 2.1) - Will not fix
Package: python-keystoneclient (Red Hat Storage 3
Debian
CVE-2014-7144: python-keystoneclient - OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 ...
vendor_debian·2014·CVSS 4.3
CVE-2014-7144 [MEDIUM] CVE-2014-7144: python-keystoneclient - OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 ...
OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.
Scope: local
bookworm: resolved (fixed in 1:0.10.1-2)
bullseye: resolved (fixed in 1:0.10.1-2)
forky: resolved (fixed in 1:0.10.1-2)
sid: resolved (fixed in 1:0.10.1-2)
trixie: resolved (fixed in 1:0.10.1-2)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2014-1783.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1784.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0020.htmlhttp://secunia.com/advisories/62709http://www.openwall.com/lists/oss-security/2014/09/25/51http://www.securityfocus.com/bid/69864http://www.ubuntu.com/usn/USN-2705-1https://bugs.launchpad.net/python-keystoneclient/+bug/1353315http://rhn.redhat.com/errata/RHSA-2014-1783.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1784.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0020.htmlhttp://secunia.com/advisories/62709http://www.openwall.com/lists/oss-security/2014/09/25/51http://www.securityfocus.com/bid/69864http://www.ubuntu.com/usn/USN-2705-1https://bugs.launchpad.net/python-keystoneclient/+bug/1353315
2014-10-02
Published