CVE-2015-7546
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly invalidate authorization tokens when using the PKI or PKIZ token providers, which allows remote authenticated users to bypass intended access restrictions and gain access to cloud resources by manipulating byte fields within a revoked token.
El servicio de identificación en OpenStack Identity (Keystone) en versiones anteriores a 2015.1.3 (Kilo) y 8.0.x en versiones anteriores a 8.0.2 (Liberty) y keystonemiddleware (anteriormente python-keystoneclient) en versiones anteriores a 1.5.4 (Kilo) y Liberty en versiones anteriores a 2.3.3 no invalida correctamente los tokens de autorización cuando utiliza los proveedores de token PKI o PKIZ, lo que permite a usuarios remotos autenticados eludir las restricciones de acceso previstas y obtener acceso a recursos de la nube manipulando los campos byte dentro de un token revocado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-09-29 CVE Reserved
- 2016-02-03 CVE Published
- 2023-11-26 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-522: Insufficiently Protected Credentials
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html | Third Party Advisory | |
http://www.securityfocus.com/bid/80498 | Third Party Advisory | |
https://bugs.launchpad.net/keystone/+bug/1490804 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security.openstack.org/ossa/OSSA-2016-005.html | 2020-06-02 |
URL | Date | SRC |
---|---|---|
https://wiki.openstack.org/wiki/OSSN/OSSN-0062 | 2020-06-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openstack Search vendor "Openstack" | Keystonemiddleware Search vendor "Openstack" for product "Keystonemiddleware" | >= 1.5.0 <= 1.5.3 Search vendor "Openstack" for product "Keystonemiddleware" and version " >= 1.5.0 <= 1.5.3" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Keystonemiddleware Search vendor "Openstack" for product "Keystonemiddleware" | >= 1.6.0 <= 2.3.2 Search vendor "Openstack" for product "Keystonemiddleware" and version " >= 1.6.0 <= 2.3.2" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Keystone Search vendor "Openstack" for product "Keystone" | >= 8.0.0 < 8.0.2 Search vendor "Openstack" for product "Keystone" and version " >= 8.0.0 < 8.0.2" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Keystone Search vendor "Openstack" for product "Keystone" | >= 2015.1.0 <= 2015.1.2 Search vendor "Openstack" for product "Keystone" and version " >= 2015.1.0 <= 2015.1.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Solaris Search vendor "Oracle" for product "Solaris" | 11.3 Search vendor "Oracle" for product "Solaris" and version "11.3" | - |
Affected
|