UBUNTU-CVE-2014-2237
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-2237
Summary:
Details: The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions.
References: https://ubuntu.com/security/CVE-2014-2237, http://www.openwall.com/lists/oss-security/2014/02/28, http://lists.openstack.org/pipermail/openstack-announce/2014-March/000204.html, https://www.cve.org/CVERecord?id=CVE-2014-2237
Affected packages
Package
Name: keystone
Purl: pkg:deb/ubuntu/keystone@1:2014.1~b3-0ubuntu3?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
