Bug 879402 (CVE-2012-5563) - CVE-2012-5563 OpenStack: Keystone extension of token validity through token chaining
Summary: CVE-2012-5563 OpenStack: Keystone extension of token validity through token c...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2012-5563
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 879405
Blocks: 873487 879404
TreeView+ depends on / blocked
 
Reported: 2012-11-22 21:29 UTC by Kurt Seifried
Modified: 2023-05-12 17:17 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2012-12-11 07:57:50 UTC
Embargoed:


Attachments (Terms of Use)
CVE-2012-5563-keystone.patch includes test case (3.29 KB, patch)
2012-11-22 21:36 UTC, Kurt Seifried
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2012:1557 0 normal SHIPPED_LIVE Moderate: openstack-keystone security, bug fix, and enhancement update 2012-12-11 02:00:31 UTC

Description Kurt Seifried 2012-11-22 21:29:11 UTC
Thierry Carrez (thierry) of the OpenStack project reports:

Anndy reported a vulnerability in token chaining in Keystone. A token
expiration date can be circumvented by creating a new token before the
old one has expired. An authenticated and authorized user could
potentially leverage this vulnerability to extend his access beyond the
account owner expectations. Note: this vulnerability was fixed in the
past (CVE-2012-3426) but was reintroduced in Folsom when code was
refactored to support PKI tokens.

Comment 1 Kurt Seifried 2012-11-22 21:36:24 UTC
Created attachment 650039 [details]
CVE-2012-5563-keystone.patch includes test case

Comment 3 Murray McAllister 2012-12-10 05:46:54 UTC
Acknowledgements:

Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Anndy as the original reporter.

Comment 4 errata-xmlrpc 2012-12-10 21:02:19 UTC
This issue has been addressed in following products:

  OpenStack Folsom for RHEL 6

Via RHSA-2012:1557 https://rhn.redhat.com/errata/RHSA-2012-1557.html

Comment 5 Fedora Update System 2012-12-11 05:56:56 UTC
openstack-keystone-2012.2.1-1.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2012-12-19 18:33:55 UTC
openstack-keystone-2012.2.1-1.el6 has been pushed to the Fedora EPEL 6 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.