CVE-2013-4294

Severity

50%

Complexity

99%

Confidentiality

48%

The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass intended access restrictions via a revoked PKI token.

The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass intended access restrictions via a revoked PKI token.

CVSS 2.0 Base Score 5. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).

Overview

Type

OpenStack Keystone

First reported 11 years ago

2013-09-23 20:55:00

Last updated 11 years ago

2013-10-31 03:34:00

Affected Software

OpenStack Keystone 2012.2

2012.2

OpenStack Keystone 2012.2.1

2012.2.1

OpenStack Keystone 2012.2.2

2012.2.2

OpenStack Keystone 2012.2.3

2012.2.3

OpenStack Keystone 2012.2.4

2012.2.4

OpenStack Keystone (Grizzly) 2013.1

2013.1

OpenStack Keystone 2013.1.1

2013.1.1

OpenStack Keystone 2013.1.2

2013.1.2

OpenStack Keystone 2013.1.3

2013.1.3

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.