CVE-2014-3621 PUBLISHED

The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.

EPSS 0.43% · 62.1th percentile

Risk Scores

EPSS Score
0.43%
62.1th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSkeystone0, 1:2013.2~rc4-0ubuntu1, 1:2013.2-0ubuntu1

Timeline

References

Open in Interactive Console →