Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-77w8-qv8m-386h

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

OpenStack Keystone Domain-scoped tokens don't get revoked

OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domain.

Пакеты

Наименование

keystone

pip
Затронутые версииВерсия исправления

< 8.0.0a0

8.0.0a0

EPSS

Процентиль: 54%
0.0031
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-613

Связанные уязвимости

ubuntu
больше 11 лет назад

OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domain.

redhat
больше 11 лет назад

OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domain.

nvd
больше 11 лет назад

OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domain.

debian
больше 11 лет назад

OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno befo ...

EPSS

Процентиль: 54%
0.0031
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-613