CVE-2014-7144 PUBLISHED

OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.

EPSS 0.37% · 58.3th percentile

Risk Scores

EPSS Score
0.37%
58.3th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSpython-keystoneclient0, 1:0.3.2-0ubuntu1, 1:0.4.1-0ubuntu1

Timeline

References

Open in Interactive Console →