CVE-2015-1852
published 2015-04-17CVE-2015-1852: The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.61%
83.8th percentile
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | python-keystoneclient | < python-keystoneclient 1:1.3.0-2 (bookworm) | python-keystoneclient 1:1.3.0-2 (bookworm) |
| debian | python-keystonemiddleware | < python-keystoneclient 1:1.3.0-2 (bookworm) | python-keystoneclient 1:1.3.0-2 (bookworm) |
| openstack | keystonemiddleware | <= 1.5.0 | — |
| openstack | keystonemiddleware | >= 0 < 1.6.0 | 1.6.0 |
| openstack | python-keystoneclient | <= 1.3.0 | — |
| openstack | python-keystoneclient | >= 0 < 1:1.3.0-2 | 1:1.3.0-2 |
| openstack | python-keystoneclient | >= 0 < 1:1.3.0-2 | 1:1.3.0-2 |
| openstack | python-keystoneclient | >= 0 < 1:1.3.0-2 | 1:1.3.0-2 |
| openstack | python-keystoneclient | >= 0 < 1:1.3.0-2 | 1:1.3.0-2 |
| openstack | python-keystoneclient | >= 0 < 1.4.0 | 1.4.0 |
| openstack | python-keystoneclient | >= 0 < 1:0.7.1-ubuntu1.2 | 1:0.7.1-ubuntu1.2 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa4.3MEDIUM
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Keystone vulnerabilities
vendor_ubuntu·2015-08-06·CVSS 4.3
CVE-2014-7144 [MEDIUM] Keystone vulnerabilities
Title: Keystone vulnerabilities
Summary: Keystone could be made to expose sensitive information over the
network.
Qin Zhao discovered Keystone disabled certification verification when
the "insecure" option is set in a paste configuration (paste.ini)
file regardless of the value, which allows remote attackers to conduct
machine-in-the-middle attacks via a crafted certificate. (CVE-2014-7144)
Brant Knudson discovered Keystone disabled certification verification when
the "insecure" option is set in a paste configuration (paste.ini)
file regardless of the value, which allows remote attackers to conduct
machine-in-the-middle attacks via a crafted certificate. (CVE-2015-1852)
Instructions: After a standard system update you need to restart Keystone to make
all the necessary changes.
Red Hat
keystonemiddleware/keystoneclient: S3Token TLS cert verification option not honored
vendor_redhat·2015-04-15·CVSS 4.3
CVE-2015-1852 [MEDIUM] CWE-295 keystonemiddleware/keystoneclient: S3Token TLS cert verification option not honored
keystonemiddleware/keystoneclient: S3Token TLS cert verification option not honored
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.
It was discovered that some items in the S3Token paste configuration as used by python-keystonemiddleware (formerly python-keystoneclient) were incorrectly evaluated as strings, an issue similar to CVE-2014-7144. If the "insecure" option were set to "false", the option would be evaluated as true, resulting in TLS connections be
Debian
CVE-2015-1852: python-keystoneclient - The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-...
vendor_debian·2015·CVSS 4.3
CVE-2015-1852 [MEDIUM] CVE-2015-1852: python-keystoneclient - The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-...
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.
Scope: local
bookworm: resolved (fixed in 1:1.3.0-2)
bullseye: resolved (fixed in 1:1.3.0-2)
forky: resolved (fixed in 1:1.3.0-2)
sid: resolved (fixed in 1:1.3.0-2)
trixie: resolved (fixed in 1:1.3.0-2)
GHSA
OpenStack keystonemiddleware and python-keystoneclient vulnerable to man-in-the-middle attacks
ghsa·2022-05-17·CVSS 4.3
CVE-2015-1852 [MEDIUM] CWE-295 OpenStack keystonemiddleware and python-keystoneclient vulnerable to man-in-the-middle attacks
OpenStack keystonemiddleware and python-keystoneclient vulnerable to man-in-the-middle attacks
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.
OSV
OpenStack keystonemiddleware and python-keystoneclient vulnerable to man-in-the-middle attacks
osv·2022-05-17·CVSS 4.3
CVE-2015-1852 [MEDIUM] OpenStack keystonemiddleware and python-keystoneclient vulnerable to man-in-the-middle attacks
OpenStack keystonemiddleware and python-keystoneclient vulnerable to man-in-the-middle attacks
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.
OSV
python-keystoneclient, python-keystonemiddleware vulnerabilities
osv·2015-08-06·CVSS 4.3
CVE-2014-7144 [MEDIUM] python-keystoneclient, python-keystonemiddleware vulnerabilities
python-keystoneclient, python-keystonemiddleware vulnerabilities
Qin Zhao discovered Keystone disabled certification verification when
the "insecure" option is set in a paste configuration (paste.ini)
file regardless of the value, which allows remote attackers to conduct
machine-in-the-middle attacks via a crafted certificate. (CVE-2014-7144)
Brant Knudson discovered Keystone disabled certification verification when
the "insecure" option is set in a paste configuration (paste.ini)
file regardless of the value, which allows remote attackers to conduct
machine-in-the-middle attacks via a crafted certificate. (CVE-2015-1852)
OSV
CVE-2015-1852: The s3_token middleware in OpenStack keystonemiddleware before 1
osv·2015-04-17·CVSS 4.3
CVE-2015-1852 [MEDIUM] CVE-2015-1852: The s3_token middleware in OpenStack keystonemiddleware before 1
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.
No detection rules found.
No public exploits indexed.
http://lists.openstack.org/pipermail/openstack-announce/2015-April/000350.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1677.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1685.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/74187http://www.ubuntu.com/usn/USN-2705-1https://bugs.launchpad.net/keystonemiddleware/+bug/1411063http://lists.openstack.org/pipermail/openstack-announce/2015-April/000350.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1677.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1685.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/74187http://www.ubuntu.com/usn/USN-2705-1https://bugs.launchpad.net/keystonemiddleware/+bug/1411063
2015-04-17
Published