Missing Required Cryptographic Step in OpenStack Keystone - CVE-2020-12692
Published: May 7, 2020 / Updated: October 6, 2021
Vulnerability details
The vulnerability allows a remote attacker to intercept and decrypt sensitive information.
The vulnerability exists due to the EC2 API does not have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an OpenStack token an unlimited number of times.
Affected software
Red Hat OpenStack for IBM Power
Red Hat OpenStack
keystone (Debian package)
openstack-keystone (Red Hat package)
keystone (Ubuntu package)
python-keystone (Ubuntu package)
Ubuntu
How to mitigate CVE-2020-12692
openstack-keystone (Red Hat package) - update to 13.0.4-3.el7ost
keystone (Ubuntu package) - update to 2:13.0.4-0ubuntu1
python-keystone (Ubuntu package) - update to 2:13.0.4-0ubuntu1