Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-2447

Опубликовано: 01 сент. 2022
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 6.6

Описание

A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

esm-infra/bionic

needed

esm-infra/focal

needed

esm-infra/xenial

needed

focal

ignored

end of standard support, was needed
jammy

released

2:21.0.1-0ubuntu2.1
kinetic

ignored

end of life, was needed
lunar

ignored

end of life, was needed
mantic

ignored

end of life, was needed

Показывать по

EPSS

Процентиль: 70%
0.00629
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
redhat
больше 3 лет назад

A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.

CVSS3: 6.6
nvd
больше 3 лет назад

A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.

CVSS3: 6.6
debian
больше 3 лет назад

A flaw was found in Keystone. There is a time lag (up to one hour in a ...

CVSS3: 8.8
github
больше 3 лет назад

A flaw was found in OpenStack. The application credential tokens can be used even after they have expired. This flaw allows an authenticated remote attacker to obtain access despite the defender's efforts to remove access.

EPSS

Процентиль: 70%
0.00629
Низкий

6.6 Medium

CVSS3