Debian Keystone vulnerabilities
45 known vulnerabilities affecting debian/keystone.
Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH11MEDIUM31LOW3
Vulnerabilities
Page 3 of 3
CVE-2012-4413P4MEDIUMCVSS 4.0fixed in keystone 2012.1.1-6 (bookworm)2012
CVE-2012-4413 [MEDIUM] CVE-2012-4413: keystone - OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or...
OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.
Scope: local
bookworm: resolved (fixed in 2012.1.1-6)
bullseye: resolved (fixed in 2012.1.1-6)
forky: resolved (fixed in 2012.1.1-6)
sid: resolved (fixed in 2012.1.1-6)
trixie: resolv
debian
CVE-2014-3621P4MEDIUMCVSS 4.0fixed in keystone 2014.1.3-1 (bookworm)2014
CVE-2014-3621 [MEDIUM] CVE-2014-3621: keystone - The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and...
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
Scope: local
bookworm: resolved (fixed in 2014.1.3-1)
bullseye: resolved (fixed in 2014.1.3-1)
debian
CVE-2015-3646P4MEDIUMCVSS 4.0fixed in keystone 2015.1.0-1 (bookworm)2015
CVE-2015-3646 [MEDIUM] CVE-2015-3646: keystone - OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs ...
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
Scope: local
bookworm: resolved (fixed in 2015.1.0-1)
bullseye: resolved (fixed in 2015.1.0-1)
forky: reso
debian
CVE-2013-4477P4LOWCVSS 3.3fixed in keystone 2013.2-2 (bookworm)2013
CVE-2013-4477 [LOW] CVE-2013-4477: keystone - The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when remov...
The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.
Scope: local
bookworm: resolved (fixed in 2013.2-2)
bullseye: resolved (fixed in 2013.2-2)
forky: resolved (fixed in 2013.2-2)
sid: resolved (fixed in 2013
debian
CVE-2013-2006P4LOWCVSS 2.1fixed in keystone 2013.1.1-2 (bookworm)2013
CVE-2013-2006 [LOW] CVE-2013-2006: keystone - OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabl...
OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.
Scope: local
bookworm: resolved (fixed in 2013.1.1-2)
bullseye: resolved (fixed in 2013.1.1-2)
forky: resolved (fixed in 2013.1.1-2)
sid: resolved (fixed i
debian
← Previous3 / 3