Safety vulnerability ID: 35373
The information on this page was manually curated by our Cybersecurity Intelligence Team.
OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.
Latest version: 26.0.0
OpenStack Identity
OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.
MLIST:[oss-security] 20120912 [OSSA 2012-014] Revoking a role does not affect existing tokens (CVE-2012-4413): http://www.openwall.com/lists/oss-security/2012/09/12/7
UBUNTU:USN-1564-1: http://www.ubuntu.com/usn/USN-1564-1
BID:55524: http://www.securityfocus.com/bid/55524
OSVDB:85484: http://osvdb.org/85484
SECUNIA:50531: http://secunia.com/advisories/50531
SECUNIA:50590: http://secunia.com/advisories/50590
XF:keystone-roles-sec-bypass(78478): https://exchange.xforce.ibmcloud.com/vulnerabilities/78478
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application