PT-2014-6367 · Openstack+1 · Openstack Identity+1
Blk-U
+1
·
Published
2014-08-15
·
Updated
2022-05-17
·
CVE-2014-5251
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Identity (Keystone) versions 2014.1.x before 2014.1.2.1
OpenStack Identity (Keystone) version Juno before Juno-3
Description
The issue is related to the MySQL token driver in OpenStack Identity (Keystone), where timestamps are stored with incorrect precision. This causes the expiration comparison for tokens to fail, allowing remote authenticated users to retain access via an expired token.
Recommendations
For OpenStack Identity (Keystone) versions 2014.1.x before 2014.1.2.1, update to version 2014.1.2.1 or later to resolve the issue.
For OpenStack Identity (Keystone) version Juno before Juno-3, update to Juno-3 or later to resolve the issue.
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openstack Identity
Ubuntu