ossa/ossa/OSSA-2014-018.yaml

62 lines
1.4 KiB
YAML

date: 2014-06-12
id: OSSA-2014-018
title: 'Keystone privilege escalation through trust chained delegation'
description: 'Steven Hardy from Red Hat reported a vulnerability in Keystone chained
delegation. By creating a delegation from a trust or OAuth token, a trustee may
abuse the identity impersonation against keystone and circumvent the enforced scope,
resulting in potential elevated privileges to any of the trustor''s projects and
or roles. All Keystone deployments configured to enable trusts are affected, which
has been the default since Grizzly.'
reference: http://lists.openstack.org/pipermail/openstack-announce/2014-June/000240.html
affected-products:
- product: keystone
version: up to 2013.2.3, and 2014.1 to 2014.1.1
vulnerabilities:
- cve-id: CVE-2014-3476
impact-assessment:
source: 'Red Hat Product Security'
rating: important
assessment:
type: CVSS2
score: 4.9
detail: AV:N/AC:M/Au:S/C:P/I:P/A:N
classification:
source: 'Red Hat Product Security'
type: CWE
detail: TODO
reporters:
- name: 'Steven Hardy'
affiliation: 'Red Hat'
reported:
- CVE-2014-3476
issues:
links:
- https://launchpad.net/bugs/1324592
type: launchpad
reviews:
juno:
- https://review.openstack.org/#/c/99687
icehouse:
- https://review.openstack.org/#/c/99700
havana:
- https://review.openstack.org/#/c/99703
type: gerrit