VulnerabilityModified
CVE-2014-3621
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the…
MEDIUM 4.0EPSS 2.13%
Does this matter?
Lower severity and a low EPSS score (2.13%). Track it; it rarely justifies an emergency change on its own.
Description
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 2.13% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- openstack/keystone · canonical/ubuntu linux · redhat/openstack
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2014-1688.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1789.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1790.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2014/09/16/10Mailing List, Patch, Third Party Advisory
- http://www.ubuntu.com/usn/USN-2406-1Third Party Advisory
- https://bugs.launchpad.net/keystone/+bug/1354208Exploit, Issue Tracking, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1688.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1789.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1790.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2014/09/16/10Mailing List, Patch, Third Party Advisory
- http://www.ubuntu.com/usn/USN-2406-1Third Party Advisory
- https://bugs.launchpad.net/keystone/+bug/1354208Exploit, Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.