CVE-2014-5251
- EPSS 0.31%
- Veröffentlicht 25.08.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users ...
- EPSS 1.04%
- Veröffentlicht 17.06.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with im...
- EPSS 2.37%
- Veröffentlicht 02.06.2014 15:55:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests.
CVE-2014-2828
- EPSS 0.86%
- Veröffentlicht 15.04.2014 14:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authent...
- EPSS 0.26%
- Veröffentlicht 01.04.2014 06:35:53
- Zuletzt bearbeitet 12.04.2025 10:46:40
The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-i...
CVE-2013-6391
- EPSS 0.5%
- Veröffentlicht 14.12.2013 17:21:46
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from ...
CVE-2013-4222
- EPSS 0.58%
- Veröffentlicht 30.09.2013 22:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
- EPSS 0.8%
- Veröffentlicht 23.09.2013 20:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass intended access res...
CVE-2013-2157
- EPSS 0.29%
- Veröffentlicht 20.08.2013 22:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
- EPSS 0.91%
- Veröffentlicht 21.05.2013 18:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain ac...