Vulnerability Bulletins

IBM Security Bulletin: IBM SmartCloud Orchestrator - Potential context confusion in Keystone middleware (CVE-2014-0105)

   
Affected software IBM
 
By doing repeated requests, with sufficient load on the target system, an authenticated user may in certain situations assume another authenticated users complete identity and multi-tenant authorizations, potentially resulting in a privilege escalation. Note that it is related to a bad interaction between eventlet and python-memcached that should be avoided if the calling process already monkey-patches "thread" to use eventlet. Only keystone middleware setups using auth_token with

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_smartcloud_orchestrator_potential_context_confusion_in_keystone_middleware_cve_2014_0105?lang=en_us