Vulnerabilities > Openstack > Keystone > 2012.2.4

DATE CVE VULNERABILITY TITLE RISK
2016-02-03 CVE-2015-7546 Insufficiently Protected Credentials vulnerability in multiple products
The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly invalidate authorization tokens when using the PKI or PKIZ token providers, which allows remote authenticated users to bypass intended access restrictions and gain access to cloud resources by manipulating byte fields within a revoked token.
6.0
2015-05-12 CVE-2015-3646 Information Exposure vulnerability in multiple products
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
network
low complexity
oracle openstack CWE-200
4.0
2014-11-03 CVE-2014-0204 Improper Privilege Management vulnerability in Openstack Keystone 2014.1
OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.
network
low complexity
openstack CWE-269
6.5
2014-06-17 CVE-2014-3476 Improper Privilege Management vulnerability in multiple products
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.
6.0
2014-06-02 CVE-2013-2014 Improper Input Validation vulnerability in multiple products
OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests.
network
low complexity
openstack fedoraproject CWE-20
5.0
2013-12-14 CVE-2013-6391 Improper Privilege Management vulnerability in multiple products
The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.
5.8
2013-08-20 CVE-2013-2157 Improper Authentication vulnerability in Openstack Keystone
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
network
openstack CWE-287
4.3
2013-04-12 CVE-2013-0282 Improper Authentication vulnerability in Openstack Keystone
OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.
network
low complexity
openstack CWE-287
5.0
2013-04-12 CVE-2013-0270 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Openstack Keystone
OpenStack Keystone Grizzly before 2013.1, Folsom, and possibly earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a large HTTP request, as demonstrated by a long tenant_name when requesting a token.
network
low complexity
openstack CWE-119
5.0