A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.
2022-09-01T21:15:09.547
2024-11-21T07:01:00.543
Modified
CVSSv3.1: 6.6 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openstack | keystone | - | Yes |
Application | redhat | openstack | 16.1 | No |
Application | redhat | openstack | 16.2 | No |
Application | redhat | openstack_platform | 16.1 | Yes |
Application | redhat | openstack_platform | 16.2 | Yes |
Application | redhat | quay | 3.0.0 | Yes |
Application | redhat | storage | 3.0 | Yes |