{"id":"DEBIAN-CVE-2015-1852","details":"The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the \"insecure\" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.","modified":"2026-09-09T06:47:30.321098758Z","published":"2015-04-17T17:59:02.653Z","upstream":["CVE-2015-1852"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2015-1852"}],"affected":[{"package":{"name":"python-keystoneclient","ecosystem":"Debian:12","purl":"pkg:deb/debian/python-keystoneclient?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.3.0-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2015-1852.json"}},{"package":{"name":"python-keystoneclient","ecosystem":"Debian:13","purl":"pkg:deb/debian/python-keystoneclient?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.3.0-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2015-1852.json"}},{"package":{"name":"python-keystoneclient","ecosystem":"Debian:14","purl":"pkg:deb/debian/python-keystoneclient?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.3.0-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2015-1852.json"}},{"package":{"name":"python-keystonemiddleware","ecosystem":"Debian:12","purl":"pkg:deb/debian/python-keystonemiddleware?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.0-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2015-1852.json"}},{"package":{"name":"python-keystonemiddleware","ecosystem":"Debian:13","purl":"pkg:deb/debian/python-keystonemiddleware?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.0-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2015-1852.json"}},{"package":{"name":"python-keystonemiddleware","ecosystem":"Debian:14","purl":"pkg:deb/debian/python-keystonemiddleware?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.0-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2015-1852.json"}}],"schema_version":"1.9.0"}