Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f82m-w3p3-cgp3

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

OpenStack Identity Keystone Improper Access Control

The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.

Пакеты

Наименование

keystone

pip
Затронутые версииВерсия исправления

>= 9.0.0, < 9.0.1

9.0.1

EPSS

Процентиль: 53%
0.00304
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 9 лет назад

The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.

redhat
больше 9 лет назад

The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.

CVSS3: 4.3
nvd
больше 9 лет назад

The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.

CVSS3: 4.3
debian
больше 9 лет назад

The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x befor ...

EPSS

Процентиль: 53%
0.00304
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-284