Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4rrr-j7ff-r844

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

python-keystoneclient missing expiration check in PKI token validation

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.

Пакеты

Наименование

python-keystoneclient

pip
Затронутые версииВерсия исправления

< 0.2.4

0.2.4

EPSS

Процентиль: 73%
0.00769
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-324

Связанные уязвимости

ubuntu
около 12 лет назад

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.

redhat
больше 12 лет назад

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.

nvd
около 12 лет назад

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.

debian
около 12 лет назад

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Fol ...

EPSS

Процентиль: 73%
0.00769
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-324