CVE-2016-4911
published 2016-06-13CVE-2016-4911: The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
1.40%
69.5th percentile
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2:9.0.0-2 (bookworm) | keystone 2:9.0.0-2 (bookworm) |
| keystone | openstack_identity | — | — |
| openstack | keystone | >= 0 < 2:9.0.0-2 | 2:9.0.0-2 |
| openstack | keystone | >= 0 < 2:9.0.0-2 | 2:9.0.0-2 |
| openstack | keystone | >= 0 < 2:9.0.0-2 | 2:9.0.0-2 |
| openstack | keystone | >= 0 < 2:9.0.0-2 | 2:9.0.0-2 |
| openstack | keystone | >= 9.0.0 < 9.0.1 | 9.0.1 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-keystone: Incorrect Audit IDs in Keystone Fernet Tokens can result in revocation bypass
vendor_redhat·2016-05-17·CVSS 4.3
CVE-2016-4911 [MEDIUM] openstack-keystone: Incorrect Audit IDs in Keystone Fernet Tokens can result in revocation bypass
openstack-keystone: Incorrect Audit IDs in Keystone Fernet Tokens can result in revocation bypass
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
Package: openstack-keystone (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: openstack-keystone (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Not affected
Package: openstack-keystone (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - Not affected
Package: openstack-keystone (Red Hat JBoss Fuse 6.2.1) - Not affected
Package: openstack-keystone (Red Hat OpenShift Enterprise 2) - Not affected
Package: openstack-keysto
Debian
CVE-2016-4911: keystone - The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (m...
vendor_debian·2016·CVSS 4.3
CVE-2016-4911 [MEDIUM] CVE-2016-4911: keystone - The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (m...
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
Scope: local
bookworm: resolved (fixed in 2:9.0.0-2)
bullseye: resolved (fixed in 2:9.0.0-2)
forky: resolved (fixed in 2:9.0.0-2)
sid: resolved (fixed in 2:9.0.0-2)
trixie: resolved (fixed in 2:9.0.0-2)
OSV
OpenStack Identity Keystone Improper Access Control
osv·2022-05-17
CVE-2016-4911 [MEDIUM] OpenStack Identity Keystone Improper Access Control
OpenStack Identity Keystone Improper Access Control
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
GHSA
OpenStack Identity Keystone Improper Access Control
ghsa·2022-05-17
CVE-2016-4911 [MEDIUM] CWE-284 OpenStack Identity Keystone Improper Access Control
OpenStack Identity Keystone Improper Access Control
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
OSV
CVE-2016-4911: The Fernet Token Provider in OpenStack Identity (Keystone) 9
osv·2016-06-13·CVSS 4.3
CVE-2016-4911 [MEDIUM] CVE-2016-4911: The Fernet Token Provider in OpenStack Identity (Keystone) 9
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4911 openstack-keystone: Incorrect Audit IDs in Keystone Fernet Tokens can result in revocation bypass
bugzilla·2016-05-18·CVSS 4.3
CVE-2016-4911 [MEDIUM] CVE-2016-4911 openstack-keystone: Incorrect Audit IDs in Keystone Fernet Tokens can result in revocation bypass
CVE-2016-4911 openstack-keystone: Incorrect Audit IDs in Keystone Fernet Tokens can result in revocation bypass
A vulnerability was found in the Keystone Fernet Token Provider. By rescoping a token a user will receive a new token without correct audit_ids, these incorrect audit_ids will prevent the entire chain of tokens from being revoked properly. This vulnerability does not impact revoking a token by it's individual audit_id. Only deployments with Keystone configured to use Fernet tokens are impacted.
References:
http://seclists.org/oss-sec/2016/q2/358
https://bugs.launchpad.net/keystone/+bug/1577558
Discussion:
Created attachment 1163873
mitaka patch
Bugzilla
CVE-2016-4911 openstack-keystone: Incorrect Audit IDs in Keystone Fernet Tokens can result in revocation bypass [openstack-rdo]
bugzilla·2016-05-18·CVSS 4.3
CVE-2016-4911 [MEDIUM] CVE-2016-4911 openstack-keystone: Incorrect Audit IDs in Keystone Fernet Tokens can result in revocation bypass [openstack-rdo]
CVE-2016-4911 openstack-keystone: Incorrect Audit IDs in Keystone Fernet Tokens can result in revocation bypass [openstack-rdo]
openstack-rdo tracking bug for openstack-keystone: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the blocked bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
This bug is against a Version which has reached End of Life.
If it's still present in supported release (http://releases.openstack.org), please update Version and reopen.
---
This bug is against a Version which has reached End of Life.
If it's still present in supported release (http://releases.openstack.org), please update Version and reopen.
---
Jon/Alan: Do you want us to have our tools
http://www.openwall.com/lists/oss-security/2016/05/17/10http://www.openwall.com/lists/oss-security/2016/05/17/11http://www.securityfocus.com/bid/90728https://bugs.launchpad.net/keystone/+bug/1577558https://review.openstack.org/#/c/311886/https://security.openstack.org/ossa/OSSA-2016-008.htmlhttp://www.openwall.com/lists/oss-security/2016/05/17/10http://www.openwall.com/lists/oss-security/2016/05/17/11http://www.securityfocus.com/bid/90728https://bugs.launchpad.net/keystone/+bug/1577558https://review.openstack.org/#/c/311886/https://security.openstack.org/ossa/OSSA-2016-008.html
2016-06-13
Published