The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
2014-10-02T14:55:03.793
2025-04-12T10:46:40.837
Deferred
CVSSv2: 4.0 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | openstack | keystone | < 2013.2.3 | Yes |
| Application | openstack | keystone | < 2014.1.2.1 | Yes |
| Operating System | canonical | ubuntu_linux | 14.04 | Yes |
| Application | redhat | openstack | 5.0 | Yes |
| Operating System | redhat | enterprise_linux | 6.0 | No |
| Operating System | redhat | enterprise_linux | 7.0 | No |
| Application | redhat | openstack | 4.0 | Yes |