CVE-2014-3621: Infoleak
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admintoken)" in the publicurl endpoint field.
Other sources
The OpenStack project reports:
"" Title: Configuration option leak through Keystone catalog Reporter: Brant Knudson (IBM) Products: Keystone Versions: up to 2013.2.3 and 2014.1 versions up to 2014.1.2.1
Description: Brant Knudson from IBM reported a vulnerability in Keystone catalog URL replacement. By creating a malicious endpoint a privileged user may reveal configuration options resulting in sensitive information, like master admintoken, being exposed through the service url. All Keystone setups that allow non-admin users to create endpoints are affected. ""
Acknowledgements:
Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Brant Knudson from IBM as the original reporter.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3621?
CVE-2014-3621 is considered a medium severity vulnerability due to its potential to expose sensitive configuration options.
How do I fix CVE-2014-3621?
To fix CVE-2014-3621, upgrade OpenStack Keystone to versions 2013.2.3 or later, or 2014.1.2.1 or later.
Who is affected by CVE-2014-3621?
CVE-2014-3621 affects users of OpenStack Keystone versions prior to 2013.2.3 and 2014.1 prior to 2014.1.2.1.
What kind of attack is possible with CVE-2014-3621?
CVE-2014-3621 allows remote authenticated users to read sensitive configuration options through a crafted URL.
Is OpenStack Keystone 4.0 vulnerable to CVE-2014-3621?
Yes, OpenStack Keystone version 4.0 is vulnerable to CVE-2014-3621.