Token Revocation Bypass in OpenStack Identity by OpenStack
CVE-2013-4294

Currently unrated

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
23 September 2013

What is CVE-2013-4294?

OpenStack Identity (Keystone) versions Folsom 2012.2.x and Grizzly prior to 2013.1.4 exhibit a significant security flaw where the mamcache and KVS token backends fail to adequately validate the revocation status of PKI tokens. This deficiency enables remote attackers to circumvent defined access controls by exploiting a revoked PKI token, potentially gaining unauthorized access to restricted resources.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.