Bug 892095 (CVE-2014-5252) - VUL-0: CVE-2014-5252: openstack-keystone: token expiration date stored incorrectly
Summary: VUL-0: CVE-2014-5252: openstack-keystone: token expiration date stored incorr...
Status: RESOLVED FIXED
Alias: CVE-2014-5252
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2014-09-03
Assignee: Bernhard Wiedemann
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/105059/
Whiteboard: maint:released:sle11-sp3-cl4:58666
Keywords:
Depends on:
Blocks:
 
Reported: 2014-08-15 12:53 UTC by Johannes Segitz
Modified: 2014-10-06 08:53 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2014-08-15 12:53:54 UTC
In Keystone V2 token support, by creating a token using the V2 API, a user may evade token revocation.
When the token is processed by the V3 API, its "issued_at" time is wrongly updated and then the service will fail to revoke it.
Only Keystone setups configured to use revocation events and UUID tokens are affected.


Commit that fixes this issue:
https://git.openstack.org/cgit/openstack/keystone/commit/?id=a4c73e4382cb062aa9f30fe1960d5014d3c49cc2

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1127250
https://bugs.launchpad.net/keystone/+bug/1348820
http://seclists.org/oss-sec/2014/q3/375
Comment 1 Swamp Workflow Management 2014-08-15 22:00:24 UTC
bugbot adjusting priority
Comment 2 Alexander Bergmann 2014-08-18 10:25:14 UTC
CVE-2014-5252 was assigned to this issue.
Comment 6 Swamp Workflow Management 2014-08-20 14:34:31 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2014-09-03.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/58665
Comment 7 SMASH SMASH 2014-08-20 14:35:17 UTC
Affected packages:

SLE-11-SP3-CLOUD4: openstack-keystone
Comment 8 Swamp Workflow Management 2014-09-26 19:04:23 UTC
SUSE-SU-2014:1219-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 892095,892097,892099
CVE References: CVE-2014-5251,CVE-2014-5252,CVE-2014-5253
Sources used:
SUSE Cloud 4 (src):    openstack-keystone-2014.1.3.dev3.gb812131-0.7.1, openstack-keystone-doc-2014.1.3.dev3.gb812131-0.7.1
Comment 9 Bernhard Wiedemann 2014-10-06 08:53:39 UTC
update is out -> fixed