Description
The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-0025 | The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions. |
Github GHSA |
GHSA-23x9-8hxr-978c | OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T10:06:00.289Z
Reserved: 2014-02-28T00:00:00.000Z
Link: CVE-2014-2237
No data.
Status : Deferred
Published: 2014-04-01T06:35:53.637
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-2237
OpenCVE Enrichment
No data.
EUVD
Github GHSA