ossa/ossa/OSSA-2014-018.yaml
Thierry Carrez 62af610079 Import basic repository structure
Prepare for repository publication by:
- moving all YAML under ossa/
- cargo-culting doc building from openstack/governance
- adding a LICENSE (CC 3.0 BY)

Change-Id: I68354a7b75060ed5012e16048e40ffb61007ff9d
2014-12-01 11:27:31 +01:00

62 lines
1.4 KiB
YAML

date: 2014-06-12
id: OSSA-2014-018
title: 'Keystone privilege escalation through trust chained delegation'
description: 'Steven Hardy from Red Hat reported a vulnerability in Keystone chained
delegation. By creating a delegation from a trust or OAuth token, a trustee may
abuse the identity impersonation against keystone and circumvent the enforced scope,
resulting in potential elevated privileges to any of the trustor''s projects and
or roles. All Keystone deployments configured to enable trusts are affected, which
has been the default since Grizzly.'
reference: http://lists.openstack.org/pipermail/openstack-announce/2014-June/000240.html
affected-products:
- product: keystone
version: up to 2013.2.3, and 2014.1 to 2014.1.1
vulnerabilities:
- cve-id: CVE-2014-3476
impact-assessment:
source: 'Red Hat Product Security'
rating: important
assessment:
type: CVSS2
score: 4.9
detail: AV:N/AC:M/Au:S/C:P/I:P/A:N
classification:
source: 'Red Hat Product Security'
type: CWE
detail: TODO
reporters:
- name: 'Steven Hardy'
affiliation: 'Red Hat'
reported:
- CVE-2014-3476
issues:
links:
- https://launchpad.net/bugs/1324592
type: launchpad
reviews:
juno:
- https://review.openstack.org/#/c/99687
icehouse:
- https://review.openstack.org/#/c/99700
havana:
- https://review.openstack.org/#/c/99703
type: gerrit