PT-2014-6369 · Openstack+1 · Openstack Identity+1

Blk-U

+1

·

Publicado

2014-08-15

·

Atualizado

2022-05-17

·

CVE-2014-5253

CVSS v4.0

7.1

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenStack Identity (Keystone) versions 2014.1.x before 2014.1.2.1 OpenStack Identity (Keystone) version Juno before Juno-3
Description The issue allows remote authenticated users to retain access via a domain-scoped token for an invalidated domain. This occurs because OpenStack Identity (Keystone) does not properly revoke tokens when a domain is invalidated.
Recommendations For OpenStack Identity (Keystone) versions 2014.1.x before 2014.1.2.1, update to version 2014.1.2.1 or later to resolve the issue. For OpenStack Identity (Keystone) version Juno before Juno-3, update to Juno-3 or later to resolve the issue.

Correção

Insufficient Session Expiration

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-5253
GHSA-77W8-QV8M-386H
PYSEC-2014-109
RHSA-2014:1121
RHSA-2014:1122
USN-2324-1

Produtos afetados

Openstack Identity
Ubuntu