CVE-2014-3621: Canonical Ubuntu Linux
Medium severity, CVSS 4.0. EPSS: 2.1% chance of exploitation in the next 30 days.
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
Affected products
- Canonical Ubuntu Linux: version 14.04 only
- Openstack Keystone: from 2013.2, before 2013.2.3 (fixed in 2013.2.3); from 2014.1, before 2014.1.2.1 (fixed in 2014.1.2.1)
- Red Hat Openstack: version 5.0 only; version 4.0 only
Published 2014-10-02. Last modified 2026-06-17.