{"id":"GHSA-p9wq-mjh8-q72m","summary":"OpenStack keystonemiddleware and python-keystoneclient vulnerable to man-in-the-middle attacks","details":"The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the \"insecure\" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.","aliases":["CVE-2015-1852","PYSEC-2015-30","PYSEC-2015-31"],"modified":"2024-09-27T18:12:14.011523Z","published":"2022-05-17T03:17:26Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-02-08T18:13:02Z","nvd_published_at":"2015-04-17T17:59:00Z","cwe_ids":["CWE-295"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1852"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2015:1677"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2015:1685"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2015-1852"},{"type":"WEB","url":"https://bugs.launchpad.net/keystonemiddleware/+bug/1411063"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1209527"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/keystonemiddleware/PYSEC-2015-30.yaml"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/python-keystoneclient/PYSEC-2015-31.yaml"},{"type":"WEB","url":"https://web.archive.org/web/20200228060649/http://www.securityfocus.com/bid/74187"},{"type":"WEB","url":"http://lists.openstack.org/pipermail/openstack-announce/2015-April/000350.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1677.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-1685.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html"},{"type":"WEB","url":"http://www.ubuntu.com/usn/USN-2705-1"}],"affected":[{"package":{"name":"keystonemiddleware","ecosystem":"PyPI","purl":"pkg:pypi/keystonemiddleware"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.0"}]}],"versions":["0","1.0.0","1.1.0","1.1.1","1.2.0","1.3.0","1.3.1","1.3.2","1.4.0","1.5.0","1.5.1","1.5.2","1.5.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-p9wq-mjh8-q72m/GHSA-p9wq-mjh8-q72m.json"}},{"package":{"name":"python-keystoneclient","ecosystem":"PyPI","purl":"pkg:pypi/python-keystoneclient"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.0"}]}],"versions":["0.1.1","0.1.2","0.1.3","0.10.0","0.10.1","0.11.0","0.11.1","0.11.2","0.2.0","0.2.1","0.2.2","0.2.3","0.2.4","0.2.5","0.3.0","0.3.1","0.3.2","0.4.0","0.4.1","0.4.2","0.5.0","0.5.1","0.6.0","0.7.0","0.7.1","0.8.0","0.9.0","1.0.0","1.1.0","1.1.1","1.2.0","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-p9wq-mjh8-q72m/GHSA-p9wq-mjh8-q72m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}