Token Revocation Bypass in OpenStack Identity by OpenStack
CVE-2013-4294
Currently unrated
Summary
OpenStack Identity (Keystone) versions Folsom 2012.2.x and Grizzly prior to 2013.1.4 exhibit a significant security flaw where the mamcache and KVS token backends fail to adequately validate the revocation status of PKI tokens. This deficiency enables remote attackers to circumvent defined access controls by exploiting a revoked PKI token, potentially gaining unauthorized access to restricted resources.
References
Timeline
Vulnerability published
Vulnerability Reserved