The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions.
2014-04-01T06:35:53.637
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openstack | keystone | 2013.1 | Yes |
Application | openstack | keystone | 2013.1.1 | Yes |
Application | openstack | keystone | 2013.1.2 | Yes |
Application | openstack | keystone | 2013.1.3 | Yes |
Application | openstack | keystone | 2013.1.4 | Yes |
Application | openstack | keystone | 2013.2.2 | Yes |