Token Revocation Bypass in OpenStack Identity by OpenStack
CVE-2013-4294

Currently unrated

Key Information:

Vendor
Openstack
Status
Vendor
CVE Published:
23 September 2013

Summary

OpenStack Identity (Keystone) versions Folsom 2012.2.x and Grizzly prior to 2013.1.4 exhibit a significant security flaw where the mamcache and KVS token backends fail to adequately validate the revocation status of PKI tokens. This deficiency enables remote attackers to circumvent defined access controls by exploiting a revoked PKI token, potentially gaining unauthorized access to restricted resources.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.