HIGH 7.5 PyPI

OpenStack keystonemiddleware and python-keystoneclient vulnerable to man-in-the-middle attacks

GHSA-p9wq-mjh8-q72m · CVE-2015-1852 · PYSEC-2015-30 · PYSEC-2015-31

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate, a different vulnerability than CVE-2014-7144.

Ready to move

Start Securing

Free, no credit card | First findings in minutes