Vulnerabilities > Openstack > Medium

DATE CVE VULNERABILITY TITLE RISK
2014-08-25 CVE-2014-5253 Credentials Management vulnerability in multiple products
OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domain.
4.9
2014-08-25 CVE-2014-5252 Credentials Management vulnerability in multiple products
The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a verification (1) GET or (2) HEAD request to v3/auth/tokens/.
4.9
2014-08-25 CVE-2014-5251 Credentials Management vulnerability in multiple products
The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.
4.9
2014-08-19 CVE-2014-4615 Information Exposure vulnerability in multiple products
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
network
low complexity
redhat canonical openstack CWE-200
5.0
2014-06-17 CVE-2014-3476 Improper Privilege Management vulnerability in multiple products
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.
6.0
2014-06-02 CVE-2013-2014 Improper Input Validation vulnerability in multiple products
OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests.
network
low complexity
openstack fedoraproject CWE-20
5.0
2014-05-14 CVE-2013-4471 Improper Authentication vulnerability in Openstack Horizon 2013.1/2013.2
The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.
network
low complexity
openstack CWE-287
5.5
2014-04-15 CVE-2014-0105 Credentials Management vulnerability in Openstack Python-Keystoneclient
The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."
network
openstack CWE-255
6.0
2014-04-01 CVE-2014-2237 Permissions, Privileges, and Access Controls vulnerability in Openstack Keystone
The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions.
network
low complexity
openstack CWE-264
5.0
2014-03-06 CVE-2013-6437 Resource Management Errors vulnerability in Openstack Nova
The libvirt driver in OpenStack Compute (Nova) before 2013.2.2 and icehouse before icehouse-2 allows remote authenticated users to cause a denial of service (disk consumption) by creating and deleting instances with unique os_type settings, which triggers the creation of a new ephemeral disk backing file.
network
low complexity
openstack CWE-399
4.0