OpenStack Keystone 授权问题漏洞

漏洞信息详情

OpenStack Keystone 授权问题漏洞

漏洞简介

Keystone中存在未授权访问漏洞。攻击者利用该漏洞获得未授权访问到受影响应用程序,有助于进一步攻击。

漏洞公告

目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:

https://github.com/openstack/keystone/commit/5438d3b5a219d7c8fa67e66e538d325a61617155

参考网址

来源: MLIST

名称: [openstack] 20120830 [OSSA 2012-013] Keystone, Lack of authorization for adding users to tenants (CVE-2012-3542)

链接:https://lists.launchpad.net/openstack/msg16282.html

来源: github.com

链接:https://github.com/openstack/keystone/commit/c13d0ba606f7b2bdc609a7f388334e5efec3f3aa

来源: github.com

链接:https://github.com/openstack/keystone/commit/5438d3b5a219d7c8fa67e66e538d325a61617155

来源: bugs.launchpad.net

链接:https://bugs.launchpad.net/keystone/+bug/1040626

来源: UBUNTU

名称: USN-1552-1

链接:http://www.ubuntu.com/usn/USN-1552-1

来源: BID

名称: 55326

链接:http://www.securityfocus.com/bid/55326

来源: MLIST

名称: [oss-security] 20120830 [OSSA 2012-013] Keystone, Lack of authorization for adding users to tenants (CVE-2012-3542)

链接:http://www.openwall.com/lists/oss-security/2012/08/30/6

来源: SECUNIA

名称: 50494

链接:http://secunia.com/advisories/50494

来源: SECUNIA

名称: 50467

链接:http://secunia.com/advisories/50467

来源:NSFOCUS
名称:20533
链接:http://www.nsfocus.net/vulndb/20533

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享