Missing Required Cryptographic Step in OpenStack Keystone - CVE-2020-12692

 

Missing Required Cryptographic Step in OpenStack Keystone - CVE-2020-12692

Published: May 7, 2020 / Updated: October 6, 2021


Vulnerability identifier: #VU27606
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12692
CWE-ID: CWE-325
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to intercept and decrypt sensitive information.

The vulnerability exists due to the EC2 API does not have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an OpenStack token an unlimited number of times.


Affected software

OpenStack Keystone
Red Hat OpenStack for IBM Power
Red Hat OpenStack
keystone (Debian package)
openstack-keystone (Red Hat package)
keystone (Ubuntu package)
python-keystone (Ubuntu package)
Ubuntu

How to mitigate CVE-2020-12692

Install update from vendor's website.

keystone (Debian package) - update to 2:14.2.0-0+deb10u1
openstack-keystone (Red Hat package) - update to 13.0.4-3.el7ost
keystone (Ubuntu package) - update to 2:13.0.4-0ubuntu1
python-keystone (Ubuntu package) - update to 2:13.0.4-0ubuntu1

External References

Related Security Bulletins