CVE-2020-12692
OpenStack Keystone does not check signature TTL of the EC2 credential auth method
5.4
MEDIUM
CVSS 3.1
EPSS 0.70%
描述
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an OpenStack token an unlimited number of times.
如何修補 CVE-2020-12692
要修補 CVE-2020-12692,請將受影響套件升級到下列已修補版本。
- —升級至 2:17.0.0~rc2-1 或更新版本
- —升級至 16.0.0 或更新版本
- —升級至 15.0.1 或更新版本
CVE-2020-12692 正在被利用嗎?
低 — EPSS 為 0.7%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 2:17.0.0~rc2-1
- >= 16.0.0.0rc1, < 16.0.0
- from 0, < 15.0.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |