Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mrxv-65rv-6hxq

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

OpenStack Keystone does not invalidate existing tokens when granting or revoking roles

OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.

Пакеты

Наименование

keystone

pip
Затронутые версииВерсия исправления

< 2012.1.3

2012.1.3

EPSS

Процентиль: 77%
0.01881
Низкий

Связанные уязвимости

ubuntu
почти 14 лет назад

OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.

redhat
почти 14 лет назад

OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.

nvd
почти 14 лет назад

OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.

debian
почти 14 лет назад

OpenStack Keystone 2012.1.3 does not invalidate existing tokens when g ...

EPSS

Процентиль: 77%
0.01881
Низкий