OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade keystone | Jul 30, 2024 | May 21, 2013 |
| Suse | — | Upgrade openstack-keystoneUpgrade python-keystoneUpgrade openstack-keystone-testUpgrade openstack-keystone-doc | Dec 12, 2013 | May 21, 2013 |
| Ubuntu | — | Upgrade python-keystone | Nov 8, 2024 | May 21, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub