OSVDB ID: 85823

Title: OpenStack Keystone Disabled Tenant Authentication Persistance

Info

Disclosure

Apr 26, 2012

Discovery

Unknown

Dates

Exploit

Apr 26, 2012

Solution

Unknown

Description

OpenStack Keystone contains a flaw that is triggered when an account associated with a disabled tenant still authenticates as if the tenant is active. This may allow a user to authenticate in some circumstances where it should not be allowed.

Classification

Location: Remote / Network Access
Attack Type: Authentication Management
Impact: Loss of Integrity
Solution: Upgrade
Exploit: Exploit Public
Disclosure: Vendor Verified
OSVDB: Authentication Required

Solution

Upgrade to version 2012.1.2 or 2012.2 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

OpenStack, LLC.

OpenStack Keystone

2012.1

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/85823