Описание
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
Ссылки
- Mailing List
- Mailing List
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Vendor Advisory
- PatchVendor Advisory
- Mailing List
- Mailing List
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Vendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Одно из
EPSS
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
Связанные уязвимости
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x befor ...
OpenStack Identity Keystone Improper Access Control
EPSS
4.3 Medium
CVSS3
4 Medium
CVSS2