Hide Forgot
Thierry Carrez (thierry) of the OpenStack project reports: Title: EC2-style credentials invalidation issue Reporter: Vijaya Erukala Products: Keystone Affects: All versions Description: Vijaya Erukala reported a vulnerability in Keystone EC2-style credentials invalidation: when a user is removed from a tenant, issued EC2-style credentials would continue to be valid for that tenant. An authenticated and authorized user could potentially leverage this vulnerability to extend his access beyond the account owner expectations. Only setups enabling EC2-style credentials (for example enabling EC2 API in Nova) are affected.
Folsom fix (included in upcoming Keystone 2012.2.1 stable update): http://github.com/openstack/keystone/commit/37308dd4f3e33f7bd0f71d83fd51734d1870713b Essex fix: http://github.com/openstack/keystone/commit/8735009dc5b895db265a1cd573f39f4acfca2a19 Grizzly (development branch) fix: http://github.com/openstack/keystone/commit/9d68b40cb9ea818c48152e6c712ff41586ad9653
Created attachment 652344 [details] OpenStack-essex-CVE-2012-5571.patch
Created attachment 652345 [details] OpenStack-folsom-CVE-2012-5571.patch
External Reference: https://bugs.launchpad.net/keystone/+bug/1064914
Acknowledgements: Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Vijaya Erukala as the original reporter.
This issue has been addressed in following products: OpenStack Folsom for RHEL 6 Via RHSA-2012:1557 https://rhn.redhat.com/errata/RHSA-2012-1557.html
This issue has been addressed in following products: OpenStack Essex for RHEL 6 Via RHSA-2012:1556 https://rhn.redhat.com/errata/RHSA-2012-1556.html
openstack-keystone-2012.1.3-3.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.
openstack-keystone-2012.2.1-1.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report.
openstack-keystone-2012.2.1-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.