CVE-2013-6391
MEDIUM severity · CVSS 5.8 · Improper privilege management
5.8CVSS MEDIUM
Summary
The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.
Impact & exploitability
Attack vectorNetwork
Attack complexity—
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impactNone
Exploit probability (EPSS)2%
AV:N/AC:M/Au:N/C:P/I:P/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://rhn.redhat.com/errata/RHSA-2014-0089.htmlAdvisory
- http://secunia.com/advisories/56079Advisory
- http://secunia.com/advisories/56154Advisory
- http://www.openwall.com/lists/oss-security/2013/12/11/7Advisory
- http://www.securityfocus.com/bid/64253Advisory
- http://www.ubuntu.com/usn/USN-2061-1Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89657Advisory
- https://bugs.launchpad.net/keystone/+bug/1242597Advisory