OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
2013-09-30T22:55:04.777
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openstack | keystone | ≤ 2013.1.3 | Yes |
Operating System | fedoraproject | fedora | 20 | Yes |
Operating System | canonical | ubuntu_linux | 12.10 | Yes |
Operating System | canonical | ubuntu_linux | 13.04 | Yes |
Application | redhat | openstack | 3.0 | Yes |