Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <50660DA7.4050507@redhat.com>
Date: Fri, 28 Sep 2012 16:50:47 -0400
From: Russell Bryant <rbryant@...hat.com>
To: "openstack@...ts.launchpad.net" <openstack@...ts.launchpad.net>,
        oss-security@...ts.openwall.com,
        openstack-announce@...ts.openstack.org
Subject: [OSSA 2012-016] Token authorization for a user in a disabled tenant
 is allowed (CVE-2012-4457)

OpenStack Security Advisory: 2012-016
CVE: CVE-2012-4457
Date: September 28, 2012
Title: Token authorization for a user in a disabled tenant is allowed
Impact: High
Reporter: Rohit Karajgi (NTT Data)
Affects: Essex (prior to 2012.1.2), Folsom (prior to folsom-3
development milestone)

Description:
Rohit Karajgi reported a vulnerability in Keystone. It was possible to
get a token that is authorized for a disabled tenant. Once the token is
established with authorization on the tenant, keystone would respond 200
OK to token validation requests from other OpenStack services, allowing
the user to work with the tenant's resources.

Folsom fix: (Included in 2012.2)
http://github.com/openstack/keystone/commit/4ebfdfaf23c6da8e3c182bf3ec2cb2b7132ef685

Essex fix: (Included in 2012.1.2)
http://github.com/openstack/keystone/commit/5373601bbdda10f879c08af1698852142b75f8d5

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=2012-4457
https://bugs.launchpad.net/keystone/+bug/988920

-- 
Russell Bryant
OpenStack Vulnerability Management Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.