CVE-2015-1852
Publication date 17 April 2015
Last updated 24 July 2024
Ubuntu priority
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.
Status
Package | Ubuntu Release | Status |
---|---|---|
python-keystoneclient | ||
14.04 LTS trusty |
Fixed 1:0.7.1-ubuntu1.2
|
|
python-keystonemiddleware | ||
14.04 LTS trusty | Not in release | |
Notes
Patch details
Package | Patch details |
---|---|
python-keystoneclient |
|
python-keystonemiddleware |
|
References
Related Ubuntu Security Notices (USN)
- USN-2705-1
- Keystone vulnerabilities
- 6 August 2015