CVE Vulnerabilities

CVE-2013-1865

Improper Authentication

Published: Mar 22, 2013 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4 MODERATE
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Folsom Openstack 2012.2 (including) 2012.2 (including)
OpenStack Folsom for RHEL 6 RedHat openstack-keystone-0:2012.2.3-7.el6ost *
Keystone Ubuntu oneiric *
Keystone Ubuntu quantal *

Potential Mitigations

References