Lucene search

K
githubGitHub Advisory DatabaseGHSA-8V8F-VC72-PMHC
HistoryMay 13, 2022 - 1:26 a.m.

OpenStack Identity Keystone Exposure of Sensitive Information

2022-05-1301:26:10
CWE-200
GitHub Advisory Database
github.com
4
openstack
keystone
exposure

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.003

Percentile

71.4%

The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by “$(admin_token)” in the publicurl endpoint field.

Affected configurations

Vulners
Node
keystonekeystoneRange<8.0.0a0
VendorProductVersionCPE
keystonekeystone*cpe:2.3:a:keystone:keystone:*:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.003

Percentile

71.4%