VDB
CVE-2013-6391
CVE-2013-6391
PUBLISHED
Reported by redhat · Published December 14, 2013
The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | *, n/a, n/a |
Timeline
- Dec 14, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 13, 2022 CVE Updated
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
References
- USN-2061-1 vendor-advisoryx_refsource_UBUNTU
- 64253 vdb-entryx_refsource_BID
- [oss-security] 20131211 [OSSA 2013-032] Keystone trust circumvention through EC2-style tokens (CVE-2013-6391) mailing-listx_refsource_MLIST
- 56154 third-party-advisoryx_refsource_SECUNIA
- 56079 third-party-advisoryx_refsource_SECUNIA
- RHSA-2014:0089 vendor-advisoryx_refsource_REDHAT
- x_refsource_CONFIRM
- keystone-cve20136391-sec-bypass(89657) vdb-entryx_refsource_XF