OpenStack Keystone EC2 credential verification Security Vulnerability
Release date:
Updated on:
Affected Systems:
Openstack Keystone 2012.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2012-5571
OpenStack Keystone is a project that provides identity, Token, directory, and policy services for the OpenStack series.
After OpenStack Keystone deletes a user from tenant, the EC2-style creden。 issued by the user are still valid and authenticated users can exploit this vulnerability to escalate their permissions. Only settings that enable EC2-style creden。 are affected by this vulnerability.
<* Source: Vijaya Erukala
Link: http://secunia.com/advisories/51423/
Https://bugzilla.redhat.com/show_bug.cgi? Id = 880399
Http://www.ubuntu.com/usn/usn-1641-1/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Ubuntu
------
Ubuntu has released a Security Bulletin (USN-1641-1) and patches for this:
USN-1641-1: USN-1641-1: OpenStack Keystone vulnerabilities
Link: http://www.ubuntu.com/usn/usn-1641-1/
Openstack
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Folsom fix (sorted ded in upcoming Keystone 2012.2.1 stable update ):
Http://github.com/openstack/keystone/commit/37308dd4f3e33f7bd0f71d83fd51734d1870713b
Essex fix:
Http://github.com/openstack/keystone/commit/8735009dc5b895db265a1cd573f39f4acfca2a19
Grizzly (development branch) fix:
Http://github.com/openstack/keystone/commit/9d68b40cb9ea818c48152e6c712ff41586ad9653