keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2013-12-27 01:55
Updated : 2014-05-05 05:21
NVD link : CVE-2013-2030
Mitre link : CVE-2013-2030
CVE.ORG link : CVE-2013-2030
JSON object : View
Products Affected
                openstack
- compute
- havana
- grizzly
- folsom
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
