Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-2447

Опубликовано: 01 сент. 2022
Источник: nvd
CVSS3: 6.6
EPSS Низкий

Описание

A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:openstack:keystone:-:*:*:*:*:*:*:*

Одно из

cpe:2.3:a:redhat:openstack:16.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:16.2:-:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:redhat:openstack_platform:16.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack_platform:16.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:storage:3.0:*:*:*:*:*:*:*

EPSS

Процентиль: 50%
0.00687
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-324
CWE-672

Связанные уязвимости

CVSS3: 6.6
ubuntu
около 4 лет назад

A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.

CVSS3: 6.6
redhat
около 4 лет назад

A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.

CVSS3: 6.6
debian
около 4 лет назад

A flaw was found in Keystone. There is a time lag (up to one hour in a ...

CVSS3: 8.8
github
около 4 лет назад

A flaw was found in OpenStack. The application credential tokens can be used even after they have expired. This flaw allows an authenticated remote attacker to obtain access despite the defender's efforts to remove access.

EPSS

Процентиль: 50%
0.00687
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-324
CWE-672