5.5
CVSSv2

CVE-2020-12692

Published: 07/05/2020 Updated: 27/04/2022
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 5.4 | Impact Score: 2.5 | Exploitability Score: 2.8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

An issue exists in OpenStack Keystone prior to 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an OpenStack token an unlimited number of times.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack keystone 16.0.0

openstack keystone

canonical ubuntu linux 18.04

Vendor Advisories

Synopsis Important: openstack-keystone security update Type/Severity Security Advisory: Important Topic An update for openstack-keystone is now available for Red Hat OpenStackPlatform 15 (Stein)Red Hat Product Security has rated this update as having a security impactof Important A Common Vulnerability Sc ...
Synopsis Important: openstack-keystone security update Type/Severity Security Advisory: Important Topic An update for openstack-keystone is now available for Red Hat OpenStackPlatform 13 (Queens)Red Hat Product Security has rated this update as having a security impactof Important A Common Vulnerability S ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: [OSSA-2020-003] Keystone: Keystone does not check signature TTL of the EC2 credential auth method (CVE PENDING) <!--X-Subj ...