Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hj89-qmx9-8qmh

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

OpenStack Identity (Keystone) improper revoking of the authentication token when deleting a user

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.

Пакеты

Наименование

keystone

pip
Затронутые версииВерсия исправления

< 8.0.0a0

8.0.0a0

EPSS

Процентиль: 75%
0.00908
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 12 лет назад

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.

redhat
больше 12 лет назад

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.

nvd
больше 12 лет назад

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.

debian
больше 12 лет назад

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly bef ...

EPSS

Процентиль: 75%
0.00908
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-287