Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:14286
HistoryMay 02, 2019 - 4:45 a.m.

Encryption And Signing Bypass

2019-05-0204:45:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.01 Low

EPSS

Percentile

83.5%

python-keystoneclient is vulnerable to Encryption and Signing Bypass. A flaw was found in the way python-keystoneclient verified data from memcached. Even when the memcache_security_strategy setting in /etc/swift/proxy-server.conf was set to MAC to perform signature checking, an attacker on the local network, or possibly an unprivileged user in a virtual machine hosted on OpenStack, could use this flaw to modify data in memcached that will later pass signature checking in python-keystoneclient.