Total vulnerabilities in the database
The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.
Software | From | Fixed in |
---|---|---|
openstack / keystone | 2013.2 | 2013.2.1 |
canonical / ubuntu_linux | 13.10 | 13.10.x |
redhat / openstack | 4.0 | 4.0.x |