CVE-2013-4222
published 2013-09-30CVE-2013-4222: OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled…
PriorityP434medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.89%
77.3th percentile
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | keystone | < keystone 2013.1.3-1 (bookworm) | keystone 2013.1.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| openstack | keystone | >= 0 < 2013.1.3-1 | 2013.1.3-1 |
| openstack | keystone | >= 0 < 2013.1.3-1 | 2013.1.3-1 |
| openstack | keystone | >= 0 < 2013.1.3-1 | 2013.1.3-1 |
| openstack | keystone | >= 0 < 2013.1.3-1 | 2013.1.3-1 |
| openstack | keystone | 2013.1 – 2013.1.3 | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g99j-vfcp-3vmf: OpenStack Identity (Keystone) Folsom, Grizzly 2013
ghsa_unreviewed·2022-05-13
CVE-2013-4222 [MEDIUM] CWE-522 GHSA-g99j-vfcp-3vmf: OpenStack Identity (Keystone) Folsom, Grizzly 2013
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
OSV
CVE-2013-4222: OpenStack Identity (Keystone) Folsom, Grizzly 2013
osv·2013-09-30·CVSS 6.5
CVE-2013-4222 [MEDIUM] CVE-2013-4222: OpenStack Identity (Keystone) Folsom, Grizzly 2013
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
Ubuntu
Keystone vulnerabilities
vendor_ubuntu·2013-10-23·CVSS 6.5
CVE-2013-4294 [MEDIUM] Keystone vulnerabilities
Title: Keystone vulnerabilities
Summary: Keystone would improperly grant access to invalid tokens under certain
circumstances.
Chmouel Boudjnah discovered that Keystone did not properly invalidate user
tokens when a tenant was disabled which allowed an authenticated user to
retain access via the token. (CVE-2013-4222)
Kieran Spear discovered that Keystone did not properly verify PKI tokens
when performing revocation when using the memcache and KVS backends. An
authenticated attacker could exploit this to bypass intended access
restrictions. (CVE-2013-4294)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
OpenStack: Keystone disabling a tenant does not disable a user token
vendor_redhat·2013-08-07·CVSS 6.5
CVE-2013-4222 [MEDIUM] CWE-613 OpenStack: Keystone disabling a tenant does not disable a user token
OpenStack: Keystone disabling a tenant does not disable a user token
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
Package: openstack-keystone (Red Hat OpenStack Platform 4) - Affected
Debian
CVE-2013-4222: keystone - OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana b...
vendor_debian·2013·CVSS 6.5
CVE-2013-4222 [MEDIUM] CVE-2013-4222: keystone - OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana b...
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
Scope: local
bookworm: resolved (fixed in 2013.1.3-1)
bullseye: resolved (fixed in 2013.1.3-1)
forky: resolved (fixed in 2013.1.3-1)
sid: resolved (fixed in 2013.1.3-1)
trixie: resolved (fixed in 2013.1.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4222 openstack-keystone: OpenStack: Keystone disabling a tenant does not disable a user token [epel-6]
bugzilla·2013-08-09·CVSS 6.5
CVE-2013-4222 [MEDIUM] CVE-2013-4222 openstack-keystone: OpenStack: Keystone disabling a tenant does not disable a user token [epel-6]
CVE-2013-4222 openstack-keystone: OpenStack: Keystone disabling a tenant does not disable a user token [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when
Bugzilla
CVE-2013-4222 OpenStack: Keystone disabling a tenant does not disable a user token
bugzilla·2013-08-09·CVSS 6.5
CVE-2013-4222 [MEDIUM] CVE-2013-4222 OpenStack: Keystone disabling a tenant does not disable a user token
CVE-2013-4222 OpenStack: Keystone disabling a tenant does not disable a user token
### Summary ###
When a tenant is disabled in Keystone, tokens that have been issued to
that tenant are not invalidated. This can result in users having access
to your cloud after you have attempted to revoke them.
### Affected Services / Software ###
Keystone
### Discussion ###
It appears that Keystone does not purge the tokens given out to tenants
when a tenant is disabled. In some scenarios this could be very
important to cloud providers. Take the case where a cloud provider must
a tenant's access because of some legal investigation. Even though the
tenant is disabled it would be possible for them to terminate VMs /
delete Swift files etc. - There are many other abuse-cases...
### Recommended Actions #
Bugzilla
CVE-2013-4222 openstack-keystone: OpenStack: Keystone disabling a tenant does not disable a user token [fedora-all]
bugzilla·2013-08-09·CVSS 6.5
CVE-2013-4222 [MEDIUM] CVE-2013-4222 openstack-keystone: OpenStack: Keystone disabling a tenant does not disable a user token [fedora-all]
CVE-2013-4222 openstack-keystone: OpenStack: Keystone disabling a tenant does not disable a user token [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when a
http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116489.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1524.htmlhttp://www.ubuntu.com/usn/USN-2002-1https://bugs.launchpad.net/ossn/+bug/1179955http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116489.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1524.htmlhttp://www.ubuntu.com/usn/USN-2002-1https://bugs.launchpad.net/ossn/+bug/1179955
2013-09-30
Published