Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 516088 (CVE-2014-3520) - sys-auth/keystone: Keystone V2 trusts privilege escalation through user supplied project id (CVE-2014-3520)
Summary: sys-auth/keystone: Keystone V2 trusts privilege escalation through user suppl...
Status: RESOLVED FIXED
Alias: CVE-2014-3520
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://seclists.org/oss-sec/2014/q3/7
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-07-02 17:52 UTC by Kristian Fiskerstrand (RETIRED)
Modified: 2014-07-02 19:23 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Kristian Fiskerstrand (RETIRED) gentoo-dev 2014-07-02 17:52:35 UTC
From ${URL}:
OpenStack Security Advisory: 2014-022
CVE: CVE-2014-3520
Date: July 02, 2014
Title: Keystone V2 trusts privilege escalation through user supplied
       project id
Reporter: Jamie Lennox (Red Hat)
Products: Keystone
Versions: up to 2013.2.3, and 2014.1 to 2014.1.1

Description:
Jamie Lennox from Red Hat reported a vulnerability in Keystone trusts.
By using an out of scope project id, a trustee may gain unauthorized
access if the trustor has the required roles in the requested project
id. All Keystone deployments configured to enable trusts and V2 API are
affected.

Juno (development branch) fix:
https://review.openstack.org/104216

Icehouse fix:
https://review.openstack.org/104217

Havana fix:
https://review.openstack.org/104218

Notes:
This fix will be included in the Juno-2 development milestone and in
future 2013.2.4 and 2014.1.2 releases.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3520
https://launchpad.net/bugs/1331912
Comment 1 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2014-07-02 19:21:27 UTC
fixed before you made the bug, kthnx