Total vulnerabilities in the database
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
Software | From | Fixed in |
---|---|---|
openstack / keystone | 2014.1 | 2014.1.2.1 |
openstack / keystone | 2013.2 | 2013.2.3 |
canonical / ubuntu_linux | 14.04 | 14.04.x |
redhat / openstack | 5.0 | 5.0.x |
redhat / openstack | 4.0 | 4.0.x |