CVE-2014-0105
Publication date 15 April 2014
Last updated 24 July 2024
Ubuntu priority
Description
The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| keystone | ||
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |
| python-keystoneclient | ||
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |
Notes
jdstrand
According to upstream, this is difficult to reliably attack since it is dependent on server interactions code present in keystone in Essex and Folsom, python-keystoneclient in Grizzly and higher
Patch details
| Package | Patch details |
|---|---|
| python-keystoneclient |