Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gmvp-5rf9-mxcm

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

OpenStack Identity (Keystone) Multiple vulnerabilities in revocation events

The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.

Пакеты

Наименование

keystone

pip
Затронутые версииВерсия исправления

< 8.0.0a0

8.0.0a0

EPSS

Процентиль: 54%
0.0031
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-613

Связанные уязвимости

ubuntu
больше 11 лет назад

The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.

redhat
больше 11 лет назад

The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.

nvd
больше 11 лет назад

The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.

debian
больше 11 лет назад

The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x befor ...

EPSS

Процентиль: 54%
0.0031
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-613