ossa/OSSA-2014-018.yaml

55 lines
1.5 KiB
YAML

advisory-date: 2014-06-12
advisory-id: OSSA-2014-018
advisory-title: 'Keystone privilege escalation through trust chained delegation'
advisory-description: 'Steven Hardy from Red Hat reported a vulnerability in Keystone
chained delegation. By creating a delegation from a trust or OAuth token, a trustee
may abuse the identity impersonation against keystone and circumvent the enforced
scope, resulting in potential elevated privileges to any of the trustor''s projects
and or roles. All Keystone deployments configured to enable trusts are affected,
which has been the default since Grizzly.'
advisory-reference: http://lists.openstack.org/pipermail/openstack-announce/2014-June/000240.html
affected-products:
- product: keystone
version: TODO
vulnerabilities:
- cve-id: CVE-2014-3476
impact-assessment:
source: 'Red Hat Product Security'
rating: important
assessment:
type: CVSS2
score: 4.9
detail: AV:N/AC:M/Au:S/C:P/I:P/A:N
classification:
source: 'Red Hat Product Security'
type: CWE
detail: TODO
reporters:
- name: 'Steven Hardy'
affiliation: 'Red Hat'
reported:
- CVE-2014-3476
notes:
issues:
issue-tracking-system-url: https://launchpad.net/bugs/{id}
issue-tracking-system-type : 'launchpad'
issue-id:
- 1324592
reviews:
review-system-url: https://review.openstack.org/#/c/{id}
review-system-type: 'gerrit'
review-id:
- 99687
- 99700
- 99703