PT-2014-6367 · Openstack+1 · Openstack Identity+1

Blk-U

+1

·

Publicado

2014-08-15

·

Atualizado

2022-05-17

·

CVE-2014-5251

CVSS v4.0

7.1

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenStack Identity (Keystone) versions 2014.1.x before 2014.1.2.1 OpenStack Identity (Keystone) version Juno before Juno-3
Description The issue is related to the MySQL token driver in OpenStack Identity (Keystone), where timestamps are stored with incorrect precision. This causes the expiration comparison for tokens to fail, allowing remote authenticated users to retain access via an expired token.
Recommendations For OpenStack Identity (Keystone) versions 2014.1.x before 2014.1.2.1, update to version 2014.1.2.1 or later to resolve the issue. For OpenStack Identity (Keystone) version Juno before Juno-3, update to Juno-3 or later to resolve the issue.

Correção

Insufficient Session Expiration

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-5251
GHSA-GMVP-5RF9-MXCM
PYSEC-2014-107
RHSA-2014:1121
RHSA-2014:1122
USN-2324-1

Produtos afetados

Openstack Identity
Ubuntu