#VU27606 Missing Required Cryptographic Step in OpenStack Keystone - CVE-2020-12692

 

#VU27606 Missing Required Cryptographic Step in OpenStack Keystone - CVE-2020-12692

Published: May 7, 2020 / Updated: October 6, 2021


Vulnerability identifier: #VU27606
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-12692
CWE-ID: CWE-325
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
OpenStack Keystone
Software vendor:
Openstack

Description

The vulnerability allows a remote attacker to intercept and decrypt sensitive information.

The vulnerability exists due to the EC2 API does not have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an OpenStack token an unlimited number of times.


Remediation

Install update from vendor's website.

External links