CVE Vulnerabilities

CVE-2014-0105

Published: Apr 15, 2014 | Modified: Dec 16, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an interaction between eventlet and python-memcached.

Affected Software

Name Vendor Start Version End Version
Python-keystoneclient Openstack * 0.4.2 (including)
Python-keystoneclient Openstack 0.2.2 (including) 0.2.2 (including)
Python-keystoneclient Openstack 0.2.3 (including) 0.2.3 (including)
Python-keystoneclient Openstack 0.2.4 (including) 0.2.4 (including)
Python-keystoneclient Openstack 0.3.0 (including) 0.3.0 (including)
Python-keystoneclient Openstack 0.3.1 (including) 0.3.1 (including)
Python-keystoneclient Openstack 0.3.2 (including) 0.3.2 (including)

References