Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4911

Опубликовано: 17 мая 2016
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)openstack-keystoneNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)openstack-keystoneNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)openstack-keystoneNot affected
Red Hat JBoss Fuse 6.2.1openstack-keystoneNot affected
Red Hat OpenShift Enterprise 2openstack-keystoneNot affected
Red Hat OpenStack Platform 8 (Liberty)openstack-keystoneNot affected
Red Hat OpenStack Platform 9 (Mitaka)openstack-keystoneNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1337079openstack-keystone: Incorrect Audit IDs in Keystone Fernet Tokens can result in revocation bypass

EPSS

Процентиль: 53%
0.00304
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 9 лет назад

The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.

CVSS3: 4.3
nvd
больше 9 лет назад

The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.

CVSS3: 4.3
debian
больше 9 лет назад

The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x befor ...

CVSS3: 4.3
github
больше 3 лет назад

OpenStack Identity Keystone Improper Access Control

EPSS

Процентиль: 53%
0.00304
Низкий

4.3 Medium

CVSS2