SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-3621

The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the…

MEDIUM 4.0EPSS 2.13%

Does this matter?

Lower severity and a low EPSS score (2.13%). Track it; it rarely justifies an emergency change on its own.

Description

The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.

CVSS 2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS
2.13% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
openstack/keystone · canonical/ubuntu linux · redhat/openstack
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.