Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2447

Опубликовано: 08 июл. 2022
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9fence-agentsNot affected
Red Hat Integration Camel K 1OpenstackNot affected
Red Hat Integration Data Virtualisation OperatorOpenstackOut of support scope
Red Hat JBoss Data Grid 7OpenstackOut of support scope
Red Hat JBoss Enterprise Application Platform 7OpenstackNot affected
Red Hat JBoss Enterprise Application Platform Expansion PackOpenstackNot affected
Red Hat JBoss Fuse 6OpenstackOut of support scope
Red Hat JBoss Fuse Service Works 6OpenstackOut of support scope
Red Hat OpenStack Platform 13 (Queens)openstack-keystoneOut of support scope
Red Hat OpenStack Platform 16.1openstack-keystoneAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-324
https://bugzilla.redhat.com/show_bug.cgi?id=2105419Openstack: Application credential token remains valid longer than expected

EPSS

Процентиль: 70%
0.00629
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
ubuntu
больше 3 лет назад

A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.

CVSS3: 6.6
nvd
больше 3 лет назад

A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.

CVSS3: 6.6
debian
больше 3 лет назад

A flaw was found in Keystone. There is a time lag (up to one hour in a ...

CVSS3: 8.8
github
больше 3 лет назад

A flaw was found in OpenStack. The application credential tokens can be used even after they have expired. This flaw allows an authenticated remote attacker to obtain access despite the defender's efforts to remove access.

EPSS

Процентиль: 70%
0.00629
Низкий

6.6 Medium

CVSS3