OpenStack keystonemiddleware and python-keystoneclient vulnerable to man-in-the-middle attacks
High severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Sep 27, 2024
Description
Published by the National Vulnerability Database
Apr 17, 2015
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Feb 8, 2023
Last updated
Sep 27, 2024
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.
References