Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-2059

Опубликовано: 09 мая 2013
Источник: redhat
CVSS2: 4

Описание

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 2.1openstack-keystoneAffected
RHOS Essex Releaseopenstack-keystoneWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-613
https://bugzilla.redhat.com/show_bug.cgi?id=960203Keystone: tokens not immediately invalidated when user is deleted

4 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.

nvd
больше 12 лет назад

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.

debian
больше 12 лет назад

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly bef ...

CVSS3: 4.3
github
больше 3 лет назад

OpenStack Identity (Keystone) improper revoking of the authentication token when deleting a user

4 Medium

CVSS2

Уязвимость CVE-2013-2059