Bug 892099 (CVE-2014-5253) - VUL-0: CVE-2014-5253: openstack-keystone: domain-scoped tokens don't get revoked
Summary: VUL-0: CVE-2014-5253: openstack-keystone: domain-scoped tokens don't get revoked
Status: RESOLVED FIXED
Alias: CVE-2014-5253
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Bernhard Wiedemann
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/105061/
Whiteboard: maint:released:sle11-sp3-cl4:58666
Keywords:
Depends on:
Blocks:
 
Reported: 2014-08-15 12:59 UTC by Johannes Segitz
Modified: 2014-10-06 08:49 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2014-08-15 12:59:26 UTC
If a domain is invalidated (which generates a revocation event), that revocation event won't match domain-scoped tokens so those tokens won't be revoked.

This is because the code to calculate the fields for a domain-scoped token don't use the domain-scope so that information can't be used when testing against the revocation events.

Upstream commit that fixes this issue:
https://git.openstack.org/cgit/openstack/keystone/commit/?id=c4447f16da036fe878382ce4e1b05b84bdcc4d4e

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1127253
https://bugs.launchpad.net/keystone/+bug/1349597
http://seclists.org/oss-sec/2014/q3/296
Comment 1 Swamp Workflow Management 2014-08-15 22:00:38 UTC
bugbot adjusting priority
Comment 2 Alexander Bergmann 2014-08-18 10:25:09 UTC
CVE-2014-5253 was assigned to this issue.
Comment 3 Vincent Untz 2014-08-19 07:35:40 UTC
For the record: this is specific to the v3 API, which is available but not really used in our product.
Comment 6 Swamp Workflow Management 2014-09-26 19:04:44 UTC
SUSE-SU-2014:1219-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 892095,892097,892099
CVE References: CVE-2014-5251,CVE-2014-5252,CVE-2014-5253
Sources used:
SUSE Cloud 4 (src):    openstack-keystone-2014.1.3.dev3.gb812131-0.7.1, openstack-keystone-doc-2014.1.3.dev3.gb812131-0.7.1
Comment 7 Bernhard Wiedemann 2014-10-06 08:49:54 UTC
this is supposed to be fixed with the update being out