Описание
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| keystone | not-affected | package | ||
| keystone | not-affected | wheezy | package | |
| python-keystoneclient | fixed | 1:0.2.5-1 | package | |
| python-keystoneclient | not-affected | wheezy | package |
Примечания
Keystone Folsom fix: https://review.openstack.org/#/c/30743/
python-keystoneclient fix: https://review.openstack.org/#/c/30742/
Starting with 2013.1-1 code in keystone/middleware/auth_token.py moved to python-keystoneclient
Связанные уязвимости
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.
python-keystoneclient missing expiration check in PKI token validation