Privilege Escalation in OpenStack Identity API by OpenStack
CVE-2013-6391

Currently unrated

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
14 December 2013

What is CVE-2013-6391?

The ec2tokens API in OpenStack Identity (Keystone) prior to the versions mentioned is susceptible to a vulnerability that enables remote trust users to exploit trust-scoped tokens. When a trust-scoped token is present, it does not return the appropriate token, allowing attackers to generate EC2 credentials from these trust-scoped tokens. This exploit can lead to potentially unauthorized access and privileges, compromising the security of the OpenStack environment.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.