Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x8h4-xf47-pqc3

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью

Описание

OpenStack Keystone Token authorization for a user in a disabled tenant is allowed

OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.

Пакеты

Наименование

Keystone

pip
Затронутые версииВерсия исправления

< 8.0.0a0

8.0.0a0

EPSS

Процентиль: 81%
0.02267
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
почти 14 лет назад

OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.

redhat
около 14 лет назад

OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.

nvd
почти 14 лет назад

OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.

debian
почти 14 лет назад

OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 do ...

EPSS

Процентиль: 81%
0.02267
Низкий

Дефекты

CWE-287