CVE-2014-0105 REJECTED

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."

EPSS 0.37% · 58.7th percentile

Risk Scores

EPSS Score
0.37%
58.7th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSkeystone0, 1:2013.2~rc4-0ubuntu1, 1:2013.2-0ubuntu1
Ubuntu:14.04:LTSpython-keystoneclient0, 1:0.3.2-0ubuntu1, 1:0.4.1-0ubuntu1

Timeline

References

Open in Interactive Console →