Candidate: CVE-2014-2237 PublicDate: 2014-04-01 06:35:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2237 http://www.openwall.com/lists/oss-security/2014/02/28 http://lists.openstack.org/pipermail/openstack-announce/2014-March/000204.html Description: The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions. Ubuntu-Description: Notes: mdeslaur> OSSA 2014-006 jdstrand> per upstream, not really triggerable by an attacker Bugs: https://launchpad.net/bugs/1260080 Priority: low Discovered-by: Morgan Fainberg Assigned-to: CVSS: Patches_keystone: upstream: https://review.openstack.org/#/c/75526/ (grizzly) upstream: https://review.openstack.org/#/c/75521/ (havana) upstream_keystone: needs-triage lucid_keystone: DNE precise_keystone: ignored (reached end-of-life) precise/esm_keystone: DNE (precise was needed) quantal_keystone: ignored (reached end-of-life) saucy_keystone: ignored (reached end-of-life) trusty_keystone: not-affected (1:2014.1~b3-0ubuntu3) trusty/esm_keystone: DNE (trusty was not-affected [1:2014.1~b3-0ubuntu3]) utopic_keystone: not-affected (1:2014.1~b3-0ubuntu3) vivid_keystone: not-affected (1:2014.1~b3-0ubuntu3) vivid/stable-phone-overlay_keystone: DNE vivid/ubuntu-core_keystone: DNE wily_keystone: not-affected (1:2014.1~b3-0ubuntu3) xenial_keystone: not-affected (1:2014.1~b3-0ubuntu3) esm-infra/xenial_keystone: not-affected (1:2014.1~b3-0ubuntu3) yakkety_keystone: not-affected (1:2014.1~b3-0ubuntu3) zesty_keystone: not-affected (1:2014.1~b3-0ubuntu3) devel_keystone: not-affected (1:2014.1~b3-0ubuntu3)