#VU27606 Missing Required Cryptographic Step in OpenStack Keystone - CVE-2020-12692
Published: May 7, 2020 / Updated: October 6, 2021
OpenStack Keystone
Openstack
Description
The vulnerability allows a remote attacker to intercept and decrypt sensitive information.
The vulnerability exists due to the EC2 API does not have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an OpenStack token an unlimited number of times.