The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass intended access restrictions via a revoked PKI token.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-0017 | The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass intended access restrictions via a revoked PKI token. |
Github GHSA |
GHSA-5qpp-v56f-mqfm | OpenStack Identity (Keystone) allows remote attackers to bypass intended access restrictions via revoked PKI token |
Ubuntu USN |
USN-2002-1 | Keystone vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T16:38:01.910Z
Reserved: 2013-06-12T00:00:00
Link: CVE-2013-4294
No data.
Status : Deferred
Published: 2013-09-23T20:55:07.323
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-4294
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN