CVE-2015-1852

UnknownEPSS 2.59%

Last modified

CVE-2015-1852 is a vulnerability of currently unknown severity. The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.. EPSS estimates a 2.59% chance of exploitation in the next 30 days.

Description

The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.

Metrics

EPSS Probability
2.59%

83.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
OpenstackKeystonemiddleware<= 1.5.0
OpenstackPython-Keystoneclient<= 1.3.0
CanonicalUbuntu Linux14.04
CanonicalUbuntu Linux15.04

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-1852?
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.
How severe is CVE-2015-1852?
Severity scoring for CVE-2015-1852 is pending analysis. The EPSS model estimates a 2.59% probability of exploitation in the next 30 days.
How do I fix CVE-2015-1852?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-1852?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST