Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-5253

Опубликовано: 28 июл. 2014
Источник: redhat
CVSS2: 4.9
EPSS Низкий

Описание

OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domain.

It was discovered that domain-scoped tokens were not revoked when a domain was disabled. Only OpenStack Identity setups configured to make use of revocation events were affected.

Отчет

This issue does not affected openstack-keystone as shipped with Red Hat Enterprise Linux OpenStack Platform 4.0.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 4openstack-keystoneNot affected
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6openstack-keystoneFixedRHSA-2014:112202.09.2014
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7openstack-keystoneFixedRHSA-2014:112102.09.2014

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-697->CWE-613
https://bugzilla.redhat.com/show_bug.cgi?id=1127253openstack-keystone: domain-scoped tokens don't get revoked

EPSS

Процентиль: 54%
0.0031
Низкий

4.9 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domain.

nvd
больше 11 лет назад

OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domain.

debian
больше 11 лет назад

OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno befo ...

CVSS3: 6.5
github
больше 3 лет назад

OpenStack Keystone Domain-scoped tokens don't get revoked

EPSS

Процентиль: 54%
0.0031
Низкий

4.9 Medium

CVSS2