CVE-2014-3476: Medium severity Openstack Keystone vulnerability
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3476?
CVE-2014-3476 is classified as a high severity vulnerability due to its potential to allow unauthorized privilege escalation.
How do I fix CVE-2014-3476?
To resolve CVE-2014-3476, upgrade OpenStack Keystone to version 2013.2.4 or later, or to version 2014.1.2 or later.
What systems are affected by CVE-2014-3476?
CVE-2014-3476 affects multiple versions of OpenStack Keystone, including those prior to 2013.2.4 and 2014.1.2.
Can CVE-2014-3476 be exploited remotely?
Yes, CVE-2014-3476 can be exploited remotely by authenticated users utilizing certain tokens.
What is the nature of the vulnerability in CVE-2014-3476?
CVE-2014-3476 involves improper handling of chained delegation, allowing privilege escalation via trust or OAuth tokens.