CVE-2013-6391
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
14/12/2013
Last modified:
11/04/2025
Description
The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.
Impact
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:* | 2013.2 (including) | 2013.2.1 (excluding) |
| cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:openstack:4.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://rhn.redhat.com/errata/RHSA-2014-0089.html
- http://secunia.com/advisories/56079
- http://secunia.com/advisories/56154
- http://www.openwall.com/lists/oss-security/2013/12/11/7
- http://www.securityfocus.com/bid/64253
- http://www.ubuntu.com/usn/USN-2061-1
- https://bugs.launchpad.net/keystone/+bug/1242597
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89657
- http://rhn.redhat.com/errata/RHSA-2014-0089.html
- http://secunia.com/advisories/56079
- http://secunia.com/advisories/56154
- http://www.openwall.com/lists/oss-security/2013/12/11/7
- http://www.securityfocus.com/bid/64253
- http://www.ubuntu.com/usn/USN-2061-1
- https://bugs.launchpad.net/keystone/+bug/1242597
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89657



