Vulnerability Name: | CVE-2014-2237 (CCN-91690) | ||||||||||||||||||||
Assigned: | 2014-03-04 | ||||||||||||||||||||
Published: | 2014-03-04 | ||||||||||||||||||||
Updated: | 2015-04-23 | ||||||||||||||||||||
Summary: | The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions. | ||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-2237 Source: REDHAT Type: UNKNOWN RHSA-2014:0580 Source: CCN Type: SA57187 OpenStack Keystone Trustee Tokens Revocation Security Bypass Security Issue Source: CCN Type: IBM Security Bulletin 1021210 SmartCloud Entry token revocation with trusts using memcache vulnerability (CVE-2014-2237) Source: CCN Type: IBM Security Bulletin 1680792 IBM SmartCloud Orchestartor - Trustee token revocation does not work with memcache backend (CVE-2014-2237) Source: MLIST Type: UNKNOWN [oss-security] 20140304 [OSSA 2014-006] Trustee token revocation does not work with memcache backend (CVE-2014-2237) Source: BID Type: UNKNOWN 65895 Source: CCN Type: BID-65895 OpenStack Keystone Trustee Token Revocation Failure Security Bypass Vulnerability Source: CCN Type: OpenStack Keystone Web Site Trustee token revocations with memcache backend (CVE-2014-2237) Source: CONFIRM Type: UNKNOWN https://bugs.launchpad.net/keystone/+bug/1260080 Source: CCN Type: Red Hat Bugzilla Bug 1071434 CVE-2014-2237 openstack-keystone: trustee token revocation does not work with memcache backend Source: XF Type: UNKNOWN keystone-cve20142237-sec-bypass(91690) | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |