Security weakness related to memcached

Bug #2045214 reported by Carmen Rata
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
StarlingX
In Progress
Undecided
Carmen Rata

Bug Description

Brief Description
-----------------

Memcached security weakness allows for acquiring a keystone token and use it to get access to StaringX web access as sysadmin.

At controller (localhost), one can obtain a token by dumping memcached with memcached_dump.
External host can get the token by accessing the Host IP and port.
The container of the host can also get token by accessing it's host IP and port (w/o root privileges).

Severity
--------

Major

Steps to Reproduce
------------------

1. use "memcached_dump" to obtain the authentication token.
2. access StaringX web with the token

Expected Behavior
------------------

Authentication token should not be exposed in clear text. It should be encrypted or not accessible.

Actual Behavior
----------------

Authentication token should is exposed

Reproducibility
---------------

<Reproducible/Intermittent/Seen once>

not 100% reproducible, some servers have the issue, some do not

Carmen Rata (crata)
Changed in starlingx:
assignee: nobody → Carmen Rata (crata)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to stx-puppet (master)

Fix proposed to branch: master
Review: https://review.opendev.org/c/starlingx/stx-puppet/+/902309

Changed in starlingx:
status: New → In Progress
Ghada Khalil (gkhalil)
information type: Public → Public Security
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to config (master)

Fix proposed to branch: master
Review: https://review.opendev.org/c/starlingx/config/+/902860

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.