CVE-2014-3621
Last modified
CVE-2014-3621 is a vulnerability of currently unknown severity. The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.. EPSS estimates a 2.11% chance of exploitation in the next 30 days.
Description
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openstack | Keystone | >= 2013.2, < 2013.2.3 |
| Openstack | Keystone | >= 2014.1, < 2014.1.2.1 |
| Canonical | Ubuntu Linux | 14.04 |
| Redhat | Openstack | 5.0 |
| Redhat | Openstack | 4.0 |
References
- http://rhn.redhat.com/errata/RHSA-2014-1688.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1789.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1790.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2014/09/16/10Mailing List, Patch, Third Party Advisory
- http://www.ubuntu.com/usn/USN-2406-1Third Party Advisory
- https://bugs.launchpad.net/keystone/+bug/1354208Exploit, Issue Tracking, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1688.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1789.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1790.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2014/09/16/10Mailing List, Patch, Third Party Advisory
- http://www.ubuntu.com/usn/USN-2406-1Third Party Advisory
- https://bugs.launchpad.net/keystone/+bug/1354208Exploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-3621?
How severe is CVE-2014-3621?
How do I fix CVE-2014-3621?
Are you affected by CVE-2014-3621?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
