Release date:
Updated on: 2012-12-01
Affected Systems:
Openstack Keystone 2012.2 (Folsom)
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56727
CVE (CAN) ID: CVE-2012-5563
OpenStack is a large-scale cloud operating system.
After the old tokens of OpenStack 2012.2 (Folsom) and other versions expire, you can create new tokens before they expire to bypass security restrictions and obtain long-term account access permissions.
<* Source: Anndy
Link: https://bugzilla.RedHat.com/show_bug.cgi? CVE-2012-5563
Http://www.securelist.com/en/advisories/50045
Http://www.openwall.com/lists/oss-security/2012/07/27/4
Http://www.Ubuntu.com/usn/usn-1641-1/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Ubuntu
------
Ubuntu has released a Security Bulletin (USN-1641-1) and patches for this:
USN-1641-1: USN-1641-1: OpenStack Keystone vulnerabilities
Link: http://www.ubuntu.com/usn/usn-1641-1/
Openstack
---------
The vendor has released a patch to fix this security problem. Please download 2012.1.1 from the vendor's homepage:
Folsom fixes:
Http://github.com/openstack/keystone/commit/375838cfceb88cacc312ff6564e64eb18ee6a355
Http://github.com/openstack/keystone/commit/628149b3dc6b58b91fd08e6ca8d91c728ccb8626
Http://github.com/openstack/keystone/commit/a67b24878a6156eab17b9098fa649f0279256f5d
Essex fixes:
Http://github.com/openstack/keystone/commit/29e74e73a6e51cffc0371b32354558391826a4aa
Http://github.com/openstack/keystone/commit/d9600434da14976463a0bd03abd8e0309f0db454
Http://github.com/openstack/keystone/commit/ea03d05ed5de0c015042876100d37a6a14bf56de