Lucene search

K
osvGoogleOSV:GHSA-4RRR-J7FF-R844
HistoryMay 17, 2022 - 4:54 a.m.

python-keystoneclient missing expiration check in PKI token validation

2022-05-1704:54:13
Google
osv.dev
8

0.002 Low

EPSS

Percentile

64.8%

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.