PT-2014-6369 · Openstack+1 · Openstack Identity+1

Blk-U

+1

·

Published

2014-08-15

·

Updated

2022-05-17

·

CVE-2014-5253

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenStack Identity (Keystone) versions 2014.1.x before 2014.1.2.1 OpenStack Identity (Keystone) version Juno before Juno-3
Description The issue allows remote authenticated users to retain access via a domain-scoped token for an invalidated domain. This occurs because OpenStack Identity (Keystone) does not properly revoke tokens when a domain is invalidated.
Recommendations For OpenStack Identity (Keystone) versions 2014.1.x before 2014.1.2.1, update to version 2014.1.2.1 or later to resolve the issue. For OpenStack Identity (Keystone) version Juno before Juno-3, update to Juno-3 or later to resolve the issue.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-5253
GHSA-77W8-QV8M-386H
PYSEC-2014-109
RHSA-2014:1121
RHSA-2014:1122
USN-2324-1

Affected Products

Openstack Identity
Ubuntu