CVE

Id
70917  
CVE No.
CVE-2014-3621  
Status
Candidate  
Description
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.  
Phase
Assigned (20140514)  
Votes
None (candidate not yet proposed)  
Comments