Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Keystone access controls could be circumvented via EC2-style tokens.
Software Description:
- keystone: OpenStack identity service
Details:
Steven Hardy discovered that Keystone did not properly enforce trusts when
using the ec2tokens API. An authenticated attacker could exploit this to
retrieve a token not scoped to the trust and elevate privileges to the
trustor's roles.
The problem can be corrected by updating your system to the following package versions: Ubuntu 13.10: python-keystone 1:2013.2-0ubuntu1.2 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-2061-1
CVE-2013-6391
Get the latest Linux and open source security news straight to your inbox.