Boletines de Vulnerabilidades

IBM Security Bulletin: IBM SmartCloud Orchestrator - Potential context confusion in Keystone middleware (CVE-2014-0105)


Información sobre el sistema

   
Software afectado IBM

Descripción

By doing repeated requests, with sufficient load on the target system, an authenticated user may in certain situations assume another authenticated users complete identity and multi-tenant authorizations, potentially resulting in a privilege escalation. Note that it is related to a bad interaction between eventlet and python-memcached that should be avoided if the calling process already monkey-patches "thread" to use eventlet. Only keystone middleware setups using auth_token with

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_smartcloud_orchestrator_potential_context_confusion_in_keystone_middleware_cve_2014_0105?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-0105 ,CVE-2014-0453 ,CVE-2014-0460 ,CVE-2014-2237 and CVE-2014-0905.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-08-06

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT