CVE-2013-6391

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
14/12/2013
Last modified:
11/04/2025

Description

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:* 2013.2 (including) 2013.2.1 (excluding)
cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:4.0:*:*:*:*:*:*:*