OpenStack token expiration Security Bypass Vulnerability

Source: Internet
Author: User

Release date:
Updated on: 2012-12-01

Affected Systems:
Openstack Keystone 2012.2 (Folsom)
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56727
CVE (CAN) ID: CVE-2012-5563

OpenStack is a large-scale cloud operating system.

After the old tokens of OpenStack 2012.2 (Folsom) and other versions expire, you can create new tokens before they expire to bypass security restrictions and obtain long-term account access permissions.

<* Source: Anndy

Link: https://bugzilla.RedHat.com/show_bug.cgi? CVE-2012-5563
Http://www.securelist.com/en/advisories/50045
Http://www.openwall.com/lists/oss-security/2012/07/27/4
Http://www.Ubuntu.com/usn/usn-1641-1/
*>

Suggestion:
--------------------------------------------------------------------------------
Vendor patch:

Ubuntu
------
Ubuntu has released a Security Bulletin (USN-1641-1) and patches for this:
USN-1641-1: USN-1641-1: OpenStack Keystone vulnerabilities
Link: http://www.ubuntu.com/usn/usn-1641-1/

Openstack
---------
The vendor has released a patch to fix this security problem. Please download 2012.1.1 from the vendor's homepage:

Folsom fixes:
Http://github.com/openstack/keystone/commit/375838cfceb88cacc312ff6564e64eb18ee6a355
Http://github.com/openstack/keystone/commit/628149b3dc6b58b91fd08e6ca8d91c728ccb8626
Http://github.com/openstack/keystone/commit/a67b24878a6156eab17b9098fa649f0279256f5d

Essex fixes:
Http://github.com/openstack/keystone/commit/29e74e73a6e51cffc0371b32354558391826a4aa
Http://github.com/openstack/keystone/commit/d9600434da14976463a0bd03abd8e0309f0db454
Http://github.com/openstack/keystone/commit/ea03d05ed5de0c015042876100d37a6a14bf56de

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.