Brant Knudson discovered that OpenStack Keystone did not properly perform input sanitization when performing endpoint catalog substitution. A remote attacker with privileged access for creating endpoints could exploit this to obtain sensitive information.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1:2014.1.3-0ubuntu2.1", "binary_name": "keystone" }, { "binary_version": "1:2014.1.3-0ubuntu2.1", "binary_name": "keystone-doc" }, { "binary_version": "1:2014.1.3-0ubuntu2.1", "binary_name": "python-keystone" } ] }