Openstack Keystone vulnerabilities
63 known vulnerabilities affecting openstack/keystone.
Total CVEs
63
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH23MEDIUM36LOW3
Vulnerabilities
Page 4 of 4
CVE-2013-4477P4LOWCVSS 3.3≥ 0, < 8.0.0a02022-05-17
CVE-2013-4477 [LOW] OpenStack Identity Keystone Privilege Escalation vulnerability
OpenStack Identity Keystone Privilege Escalation vulnerability
The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.
ghsaosv
CVE-2012-5483P4LOWCVSS 2.1v2012.1.32012-12-26
CVE-2012-5483 [LOW] CWE-264 CVE-2012-5483: tools/sample_data.sh in OpenStack Keystone 2012.1.3, when access to Amazon Elastic Compute Cloud (Am
tools/sample_data.sh in OpenStack Keystone 2012.1.3, when access to Amazon Elastic Compute Cloud (Amazon EC2) is configured, uses world-readable permissions for /etc/keystone/ec2rc, which allows local users to obtain access to EC2 services by reading administrative access and secret values from this file.
nvd
CVE-2013-2006P4LOWCVSS 2.1v2013.1.12013-05-21
CVE-2013-2006 [LOW] CWE-200 CVE-2013-2006: OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) adm
OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.
ghsanvdosv
← Previous4 / 4