296,746
Total vulnerabilities in the database
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
| Software | From | Fixed in |
|---|---|---|
| openstack / keystone | 2014.1 | 2014.1.2.1 |
| openstack / keystone | 2013.2 | 2013.2.3 |
| canonical / ubuntu_linux | 14.04 | 14.04.x |
| redhat / openstack | 5.0 | 5.0.x |
| redhat / openstack | 4.0 | 4.0.x |