cbcvebase.

Debian Keystone vulnerabilities

45 known vulnerabilities affecting debian/keystone.

Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH11MEDIUM31LOW3

Vulnerabilities

Page 2 of 3
CVE-2014-0204P4MEDIUMCVSS 6.5fixed in keystone 2014.1-5 (bookworm)2014
CVE-2014-0204 [MEDIUM] CVE-2014-0204: keystone - OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a ro... OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID. Scope: local bookworm: resolved (fixed in 2014.1-5) bullseye: resolved (fixed in 2014.1-5) forky: resolved (fixed in 2014.1
debian
CVE-2012-5571P4MEDIUMCVSS 5.4fixed in keystone 2012.1.1-11 (bookworm)2012
CVE-2012-5571 [MEDIUM] CVE-2012-5571: keystone - A flaw was found in OpenStack Keystone. This vulnerability allows remote authent... A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly handle EC2 (Elastic Compute Cloud) tokens when a user's role has been removed from a tenant. An attacker can leverage a token associated with a removed user role to gain
debian
CVE-2014-3476P4MEDIUMCVSS 6.0fixed in keystone 2014.1.1-2 (bookworm)2014
CVE-2014-3476 [MEDIUM] CVE-2014-3476: keystone - OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno ... OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles. Scope: local bookworm: resolved (fixed in 2014.1.1-2
debian
CVE-2014-0105P4MEDIUMCVSS 6.0fixed in keystone 2013.1.1-2 (bookworm)2014
CVE-2014-0105 [MEDIUM] CVE-2014-0105: keystone - The auth_token middleware in the OpenStack Python client library for Keystone (a... The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached." Scope
debian
CVE-2013-4294P4MEDIUMCVSS 5.0fixed in keystone 2013.1.3-2 (bookworm)2013
CVE-2013-4294 [MEDIUM] CVE-2013-4294: keystone - The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Fol... The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass intended access restrictions via a revoked PKI token. Scope: local bookworm: resolved (fixed in 2013.1.3-2) bullseye: resolved (fixed in
debian
CVE-2012-3426P4MEDIUMCVSS 4.9fixed in keystone 2012.1.1-1 (bookworm)2012
CVE-2012-3426 [MEDIUM] CVE-2012-3426: keystone - OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 ... OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging
debian
CVE-2013-0282P4MEDIUMCVSS 5.0fixed in keystone 2012.1.1-13 (bookworm)2013
CVE-2013-0282 [MEDIUM] CVE-2013-0282: keystone - OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex... OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions. Scope: local bookworm: resolved (fixed in 2012.1.1-13) bullseye: resolved (fixed in 2012.1.1-13) fo
debian
CVE-2014-5252P4MEDIUMCVSS 4.9fixed in keystone 2014.1.2.1-1 (bookworm)2014
CVE-2014-5252 [MEDIUM] CVE-2014-5252: keystone - The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno ... The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a verification (1) GET or (2) HEAD request to v3/auth/tokens/. Scope: local bookworm: resolved (fixed in 2014.1.2.1-1) bullseye: res
debian
CVE-2013-1664P4MEDIUMCVSS 5.0fixed in cinder 2012.2.3-1 (bookworm)2013
CVE-2013-1664 [MEDIUM] CVE-2013-1664: cinder - The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenSt... The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. Scope: local bookworm: resolved (fixe
debian
CVE-2013-2104P4LOWCVSS 5.5fixed in python-keystoneclient 1:0.2.5-1 (bookworm)2013
CVE-2013-2104 [MEDIUM] CVE-2013-2104: keystone - python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does... python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2013-2255P4MEDIUMCVSS 5.9fixed in keystone 2014.1-1 (bookworm)2013
CVE-2013-2255 [MEDIUM] CVE-2013-2255: keystone - HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possi... HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates. Scope: local bookworm: resolved (fixed in 2014.1-1) bullseye: resolved (fixed in 2014.1-1) forky: resolved (fixed in 2014.1-1) sid: resolved (fixed in 2014.1-1) trixie: resolved (fixed in 2014.1-1)
debian
CVE-2020-12692P4MEDIUMCVSS 5.4fixed in keystone 2:17.0.0~rc2-1 (bookworm)2020
CVE-2020-12692 [MEDIUM] CVE-2020-12692: keystone - An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2... An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an OpenStack token an unlimited number of times. Scope: local bookworm: resolved (fixed in 2:17.0.0~rc2-1) bullseye: resolved (fixed in 2:17.0.0~rc2
debian
CVE-2014-5251P4MEDIUMCVSS 4.9fixed in keystone 2014.1.2.1-1 (bookworm)2014
CVE-2014-5251 [MEDIUM] CVE-2014-5251: keystone - The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2... The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token. Scope: local bookworm: resolved (fixed in 2014.1.2.1-1) bullseye: resolved (fi
debian
CVE-2014-5253P4MEDIUMCVSS 4.9fixed in keystone 2014.1.2.1-1 (bookworm)2014
CVE-2014-5253 [MEDIUM] CVE-2014-5253: keystone - OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 ... OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domain. Scope: local bookworm: resolved (fixed in 2014.1.2.1-1) bullseye: resolved (fixed in 2014.1.2.1-1) forky: resolved (fixed in
debian
CVE-2012-3542P4MEDIUMCVSS 5.8fixed in keystone 2012.1.1-5 (bookworm)2012
CVE-2012-3542 [MEDIUM] CVE-2012-3542: keystone - OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack ... OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that i
debian
CVE-2013-2014P4MEDIUMCVSS 5.0fixed in keystone 2013.1.1-2 (bookworm)2013
CVE-2013-2014 [MEDIUM] CVE-2013-2014: keystone - OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a d... OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests. Scope: local bookworm: resolved (fixed in 2013.1.1-2) bullseye: resolved (fixed in 2013.1.1-2) forky: resolved (fixed in 2013.1.1-2) sid: resolved (fixed in 2013.1.1-2) trixie: resolved (fixed in 2013.1.1-2)
debian
CVE-2013-0247P4MEDIUMCVSS 5.0fixed in keystone 2012.1.1-12 (bookworm)2013
CVE-2013-0247 [MEDIUM] CVE-2013-0247: keystone - OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and ... OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries. Scope: local bookworm: resolved (fixed in 2012.1.1-12) bullseye: resolved (fixed in 2012.1.1-12) forky:
debian
CVE-2014-2237P4MEDIUMCVSS 5.0fixed in keystone 2013.2.3-1 (bookworm)2014
CVE-2014-2237 [MEDIUM] CVE-2014-2237: keystone - The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013... The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass
debian
CVE-2016-4911P4MEDIUMCVSS 4.3fixed in keystone 2:9.0.0-2 (bookworm)2016
CVE-2016-4911 [MEDIUM] CVE-2016-4911: keystone - The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (m... The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token. Scope: local bookworm: resolved (fixed in 2:9.0.0-2) bullseye: resolved (fixed in 2:9.0.0-2) forky: resolved (fixed in 2:9.0.0-2) sid: resolv
debian
CVE-2012-4457P4MEDIUMCVSS 4.0fixed in keystone 2012.1.1-9 (bookworm)2012
CVE-2012-4457 [MEDIUM] CVE-2012-4457: keystone - OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not pro... OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant. Scope: local bookworm: resolved (fixed in 2012.1.1-9) bullseye: resolved (fixed in 2012.1.1-9) forky: resolved (fixed in
debian
Debian Keystone vulnerabilities | cvebase