The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade keystone | Jul 30, 2024 | Oct 2, 2014 |
| Oracle Solaris | — | Upgrade cloud/openstack/keystone to version 0.2013.2.3-0.175.2.3.0.4.0 on Solaris 11.2 | May 29, 2017 | Oct 2, 2014 |
| Ubuntu | — | Upgrade python-keystone | Nov 8, 2024 | Oct 2, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub