OpenStack Keystone 在 29.0.3 之前存在以下问题: 通过委托认证方式(包括 EC2 凭据、应用凭据、OAuth1 访问令牌和信任关系)获取的令牌,并未被阻止通过 API 创建、修改或删除凭据。此外,由 EC2 派生的令牌还可以读取凭据内容(credential blobs),从而可能泄露 TOTP 多因子认证种子(seeds)及其他机密信息。同时, 接口未校验更新后请求中的 ,导致任意委托令牌可以将凭据移至未授权的项目。所有使用委托认证的 Keystone 部署均受此漏洞影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet