[pre-OSSA] Vulnerability in OpenStack keystonemiddleware (CVE-2015-1852)
Bug #1442579 reported by
Alexander Makarov
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Mirantis OpenStack |
Fix Released
|
Critical
|
Alexander Makarov | ||
5.0.x |
Fix Committed
|
Critical
|
Alexander Makarov | ||
5.1.x |
Fix Released
|
Critical
|
Alexander Nevenchannyy | ||
6.0.x |
Fix Released
|
Critical
|
Alexander Nevenchannyy | ||
6.1.x |
Fix Released
|
Critical
|
Alexander Makarov | ||
7.0.x |
Fix Released
|
Critical
|
Alexander Makarov |
Bug Description
Brant Knudson from IBM reported a vulnerability in keystonemiddleware
(formerly shipped as python-
is set in a S3Token paste configuration file its value is effectively
ignored and instead assumed to be true. As a result certificate
verification will be disabled, leaving TLS connections open to MITM
attacks. Note that it's unusual to explicitly add this option and then
set it to false, so the impact of this bug is thought to be limited. All
versions of s3_token middleware with TLS settings configured are
affected by this flaw.
CVE References
information type: | Private Security → Private |
information type: | Private → Private Security |
information type: | Private Security → Public Security |
tags: | added: feature-security |
To post a comment you must log in.
On verification in 6.1.x