A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2022-09-01T20:30:20

Updated: 2024-08-03T00:39:07.647Z

Reserved: 2022-07-16T00:00:00

Link: CVE-2022-2447

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-09-01T21:15:09.547

Modified: 2022-10-01T02:29:47.277

Link: CVE-2022-2447

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-07-08T00:00:00Z

Links: CVE-2022-2447 - Bugzilla