Lucene search

K
githubGitHub Advisory DatabaseGHSA-HJ89-QMX9-8QMH
HistoryMay 17, 2022 - 1:36 a.m.

OpenStack Identity (Keystone) improper revoking of the authentication token when deleting a user

2022-05-1701:36:23
CWE-287
GitHub Advisory Database
github.com
5
openstack
identity
keystone
revoking
authentication
token
deleting
user
folsom
grizzly
havana
remote
authenticated

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.013

Percentile

86.1%

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.

Affected configurations

Vulners
Node
keystone-enginekeystoneRange<8.0.0a0

References

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.013

Percentile

86.1%