{"id":"GHSA-8v8f-vc72-pmhc","summary":"OpenStack Identity Keystone Exposure of Sensitive Information","details":"The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by \"$(admin_token)\" in the publicurl endpoint field.","aliases":["CVE-2014-3621","PYSEC-2026-653"],"modified":"2026-07-06T08:11:06.889040322Z","published":"2022-05-13T01:26:10Z","database_specific":{"cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-05-14T20:48:03Z","nvd_published_at":"2014-10-02T14:55:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3621"},{"type":"WEB","url":"https://github.com/openstack/keystone/commit/2989ff257e4fde6a168e25b926805e700406aa80"},{"type":"WEB","url":"https://github.com/openstack/keystone/commit/52714633c9a4dae5e60279217090859aa6dbcb4f"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2014:1688"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2014:1789"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2014:1790"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2014-3621"},{"type":"WEB","url":"https://bugs.launchpad.net/keystone/+bug/1354208"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1139937"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1688.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1789.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1790.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2014/09/16/10"},{"type":"WEB","url":"http://www.ubuntu.com/usn/USN-2406-1"}],"affected":[{"package":{"name":"keystone","ecosystem":"PyPI","purl":"pkg:pypi/keystone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.0.0a0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-8v8f-vc72-pmhc/GHSA-8v8f-vc72-pmhc.json"}}],"schema_version":"1.9.0"}