Token Revocation Bypass in OpenStack Identity by OpenStack
CVE-2013-4294

Currently unrated

Key Information:

Vendor
Openstack
Status
Vendor
CVE Published:
23 September 2013

Summary

OpenStack Identity (Keystone) versions Folsom 2012.2.x and Grizzly prior to 2013.1.4 exhibit a significant security flaw where the mamcache and KVS token backends fail to adequately validate the revocation status of PKI tokens. This deficiency enables remote attackers to circumvent defined access controls by exploiting a revoked PKI token, potentially gaining unauthorized access to restricted resources.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.