Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Brief introduction CVE-2021-3563 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3714-1
Several security issues were fixed in OpenStack Keystone.. =========================================================================Ubuntu Security Notice USN-4480-1 September 01, 2020 keystone vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Several security issues were fixed in OpenStack Keystone. Software Description: - keystone: OpenStack identity service Details: It was discovered that OpenStack Keystone incorrectly handled EC2 credentials. An authenticated attacker with a limited scope could possibly create EC2 credentials with escalated permissions. (CVE-2020-12689, CVE-2020-12691) It was discovered that OpenStack Keystone incorrectly handled the list of roles provided with OAuth1 access tokens. An authenticated user could possibly end up with more role assignments than intended. (CVE-2020-12690) It was discovered that OpenStack Keystone incorrectly handled EC2 signature TTL checks. A remote attacker could possibly use this issue to reuse Authorization headers. (CVE-2020-12692) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: keystone 2:13.0.4-0ubuntu1 python-keystone 2:13.0.4-0ubuntu1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4480-1 CVE-2020-12689, CVE-2020-12690, CVE-2020-12691, CVE-2020-12692 Package Information: https://launchpad.net/ubuntu/+source/keystone/2:13.0.4-0ubuntu1 . Ubuntu 18.04 LTS Glance security patch resolves multiple elevation of privilege vulnerabilities.. Ubuntu Security, Keystone Issues, OpenStack Updates, Authentication Bugs. . Severity: Critical. LinuxSecurity.com Team
A vulnerability was found in the EC2 credentials API of Keystone, the OpenStack identity service: Any user authenticated within a limited scope (trust/oauth/application credential) could create an EC2 credential with an escalated permission, such as obtaining "admin" while . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4679-1
An update for openstack-keystone is now available for Red Hat OpenStack Platform 15 (Stein). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: openstack-keystone security update Advisory ID: RHSA-2019:4358-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2019:4358 Issue date: 2019-12-19 CVE Names: CVE-2019-19687 ==================================================================== 1. Summary: An update for openstack-keystone is now available for Red Hat OpenStack Platform 15 (Stein). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 15.0 - noarch 3. Description: The OpenStack Identity service (keystone) authenticates and authorizes OpenStack users by keeping track of users and their permitted activities. The Identity service supports multiple forms of authentication, including user name and password credentials, token-based systems, and AWS-style logins. Security Fix(es): * Credentials API allows non-admin to list and retrieve all userscredentials (CVE-2019-19687) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed(https://bugzilla.redhat.com/): 1781470 - CVE-2019-19687 openstack-keystone: Credentials API allows non-admin to list and retrieve all users credentials 6. Package List: Red Hat OpenStack Platform 15.0: Source: openstack-keystone-15.0.1-0.20190720060412.5f27c4b.1.el8ost.src.rpm noarch: openstack-keystone-15.0.1-0.20190720060412.5f27c4b.1.el8ost.noarch.rpm python3-keystone-15.0.1-0.20190720060412.5f27c4b.1.el8ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-19687 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXfvPCtzjgjWX9erEAQhscA/+JPQtUDhyQwtzei16r9+RMXMNu9kzScZc ZaRJXZuF3nyG3qoOI2GPoS8Vn3oVvW2sHgpJczoWusW2tBtuupPK02ezuRFCNx31 i8PqIu9WYJL11UeCSrlyemIC6c0VR4K5+b/i+crmDvBoTzJLDL7TUb8EqznjhGhA lvFAvEGbAE2yM8YXMS/mMh/1VK8Mxo7jIYXLODr1rV6x1F+9SquYcnKC8ehMNfui ZuOlConk+cZtJuU29VR0d6JVNox9VQujT0nLyUyAJBE3ZMm5YgwBps9WGunTpTcJ UDWal2TMGEXxtE+LZrK4aeNoZvsKGVHxVYcry9zcKW94/k84krSW8PixUxZBNTXc xm+Dbk1twjsnnJq2nNL/FdujExs1O8YO30t5Ruy1oIYqKOShMkBhfhcnjLccytTf L4x3+n8vtFHTEreT5/Ie3QW5AVxUwsaWSxoMkg+9NyMEdbnVW5VIpuFJ6NlmilBC 4R4aMz5u0RRTxkElAgJVirQ9NogKNmUK1G/7O9LkBEMDUScWuqvTPIS18zrM7Kb+ Z/zGmD2ObTqP6x5zKSbvxYigqCdr0UzEz34zvlCi2qsbQereMwvTunNEebJTsayX RRt3Bjdyy1SBgLn1XvNDOS86MyNjM/Wu33Abv+f476luNT+1cnmj6ZfhprqiUYvQ XrjAwnHgF+w=XY9T -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Kristi Nikolla discovered an information leak in Keystone, the OpenStack identity service, if running in a federated setup. For the stable distribution (stretch), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4275-1
Keystone could be made to expose sensitive information over thenetwork.. =========================================================================Ubuntu Security Notice USN-2705-1 August 06, 2015 python-keystoneclient, python-keystonemiddleware vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 - Ubuntu 14.04 LTS Summary: Keystone could be made to expose sensitive information over the network. Software Description: - python-keystoneclient: Client library for OpenStack Identity API - python-keystonemiddleware: Client library for OpenStack Identity API Details: Qin Zhao discovered Keystone disabled certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate. (CVE-2014-7144) Brant Knudson discovered Keystone disabled certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate. (CVE-2015-1852) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: python-keystoneclient 1:1.2.0-0ubuntu1.1 python-keystonemiddleware 1.5.0-0ubuntu1.1 Ubuntu 14.04 LTS: python-keystoneclient 1:0.7.1-ubuntu1.2 After a standard system update you need to restart Keystone to make all the necessary changes. References: CVE-2014-7144, CVE-2015-1852 Package Information: https://launchpad.net/ubuntu/+source/python-keystoneclient/1:1.2.0-0ubuntu1.1 https://launchpad.net/ubuntu/+source/python-keystonemiddleware/1.5.0-0ubuntu1.1 https://launchpad.net/ubuntu/+source/python-keystoneclient/1:0.7.1-ubuntu1.2 . Secure your Keystone deployment on Ubuntu by updating packages, reviewingconfigs, enforcing secure networking, and regularly monitoring logs for better protection. Keystone Security Issues, Ubuntu Updates, Man-in-the-Middle Attack, Python Keystone Client, Client Library Security. . Severity: Important. LinuxSecurity.com Team
Updated openstack-keystone packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 6. [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Important: openstack-keystone security and bug fix update Advisory ID: RHSA-2014:1789-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2014:1789.html Issue date: 2014-11-03 CVE Names: CVE-2014-3621 ==================================================================== 1. Summary: Updated openstack-keystone packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6 - noarch 3. Description: The OpenStack Identity service (keystone) authenticates and authorizes OpenStack users by keeping track of users and their permitted activities. The Identity service supports multiple forms of authentication, including user name and password credentials, token-based systems, and AWS-style logins. A flaw was found in the keystone catalog URL replacement. A user with permissions to register an endpoint could use this flaw to leak configuration data, including the master admin_token. Only keystone setups that allow non-cloud-admin users to create endpoints were affected by this issue. (CVE-2014-3621) Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Brant Knudson from IBM as the original reporter. The openstack-keystone packages havebeen upgraded to upstream version 2014.1.3, which provides a number of bug fixes over the previous version. (BZ#1149748) All openstack-keystone users are advised to upgrade to these updated packages, which correct these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1139937 - CVE-2014-3621 openstack-keystone: configuration data information leak through Keystone catalog 1149748 - Rebase openstack-keystone to 2014.1.3 6. Package List: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6: Source: openstack-keystone-2014.1.3-2.el6ost.src.rpm noarch: openstack-keystone-2014.1.3-2.el6ost.noarch.rpm openstack-keystone-doc-2014.1.3-2.el6ost.noarch.rpm python-keystone-2014.1.3-2.el6ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2014-3621 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2014 Red Hat, Inc. . Revised openstack-keystone software resolves a security vulnerability and various bugs in Red Hat Enterprise Linux OpenStack Platform version 5.0.. OpenStack Security Fix, Red Hat Update, Keystone Configuration Leak. . Severity: Important. LinuxSecurity.com Team
Updated openstack-keystone packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 7. [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Important: openstack-keystone security and bug fix update Advisory ID: RHSA-2014:1790-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2014:1790.html Issue date: 2014-11-03 CVE Names: CVE-2014-3621 ==================================================================== 1. Summary: Updated openstack-keystone packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7 - noarch 3. Description: The OpenStack Identity service (keystone) authenticates and authorizes OpenStack users by keeping track of users and their permitted activities. The Identity service supports multiple forms of authentication, including user name and password credentials, token-based systems, and AWS-style logins. A flaw was found in the keystone catalog URL replacement. A user with permissions to register an endpoint could use this flaw to leak configuration data, including the master admin_token. Only keystone setups that allow non-cloud-admin users to create endpoints were affected by this issue. (CVE-2014-3621) Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Brant Knudson from IBM as the original reporter. The openstack-keystone packages havebeen upgraded to upstream version 2014.1.3, which provides a number of bug fixes over the previous version. (BZ#1149736) All openstack-keystone users are advised to upgrade to these updated packages, which correct these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1113534 - LDAP misconfiguration should be handled better 1116551 - Can't get a token with curl when keystone is running in Apache with LDAP 1139937 - CVE-2014-3621 openstack-keystone: configuration data information leak through Keystone catalog 1140152 - Keystone LDAPS connection using CA certificate 1149425 - Include policy.v3cloudsample.json example 1149736 - Rebase openstack-keystone to 2014.1.3 6. Package List: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7: Source: openstack-keystone-2014.1.3-2.el7ost.src.rpm noarch: openstack-keystone-2014.1.3-2.el7ost.noarch.rpm openstack-keystone-doc-2014.1.3-2.el7ost.noarch.rpm python-keystone-2014.1.3-2.el7ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2014-3621 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2014 Red Hat, Inc. . Recent updates to openstack-keystone packages address a security vulnerability and various bugs for the Red Hat Enterprise Linux OpenStack Platform.. OpenStack Security Fix, Red Hat Update, Keystone Bug Fix, Linux OpenStack. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.