Missing Required Cryptographic Step in OpenStack Keystone - CVE-2020-12692

 

Missing Required Cryptographic Step in OpenStack Keystone - CVE-2020-12692

Published: May 7, 2020 / Updated: October 6, 2021


Vulnerability identifier: #VU27606
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-12692
CWE-ID: CWE-325
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Openstack
Affected software:
OpenStack Keystone

Detailed vulnerability description

The vulnerability allows a remote attacker to intercept and decrypt sensitive information.

The vulnerability exists due to the EC2 API does not have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an OpenStack token an unlimited number of times.


How to mitigate CVE-2020-12692

Install update from vendor's website.

Sources