Description
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4 Affected Packages3 packages
Also affects: Fedora 20, Ubuntu Linux 12.10, 13.04
🔴Vulnerability Details
3GHSAGHSA-g99j-vfcp-3vmf: OpenStack Identity (Keystone) Folsom, Grizzly 2013↗2022-05-13 ▶ CVEListCVE-2013-4222: OpenStack Identity (Keystone) Folsom, Grizzly 2013↗2013-09-30 ▶ OSVCVE-2013-4222: OpenStack Identity (Keystone) Folsom, Grizzly 2013↗2013-09-30 ▶ 📋Vendor Advisories
3UbuntuKeystone vulnerabilities↗2013-10-23 ▶ Red HatOpenStack: Keystone disabling a tenant does not disable a user token↗2013-08-07 ▶ DebianCVE-2013-4222: keystone - OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana b...↗2013 ▶ 💬Community
3BugzillaCVE-2013-4222 openstack-keystone: OpenStack: Keystone disabling a tenant does not disable a user token [epel-6]↗2013-08-09 ▶ BugzillaCVE-2013-4222 OpenStack: Keystone disabling a tenant does not disable a user token↗2013-08-09 ▶ BugzillaCVE-2013-4222 openstack-keystone: OpenStack: Keystone disabling a tenant does not disable a user token [fedora-all]↗2013-08-09 ▶