Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS13NjZwLTc4ZzQtbXI3Z84AAZ-d

OpenStack Keystone Insufficient token expiration

OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.

Permalink: https://github.com/advisories/GHSA-w66p-78g4-mr7g
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13NjZwLTc4ZzQtbXI3Z84AAZ-d
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 2 years ago
Updated: 4 months ago


Identifiers: GHSA-w66p-78g4-mr7g, CVE-2012-5563
References: Repository: https://github.com/openstack/keystone
Blast Radius: 0.0

Affected Packages

pypi:keystone
Dependent packages: 3
Dependent repositories: 37
Downloads: 6,744 last month
Affected Version Ranges: < 8.0.0
Fixed in: 8.0.0
All affected versions:
All unaffected versions: 12.0.2, 12.0.3, 13.0.2, 13.0.3, 13.0.4, 14.0.0, 14.0.1, 14.1.0, 14.2.0, 15.0.0, 15.0.1, 16.0.0, 16.0.1, 16.0.2, 17.0.0, 17.0.1, 18.0.0, 18.1.0, 19.0.0, 19.0.1, 20.0.0, 20.0.1, 21.0.0, 21.0.1, 22.0.0, 22.0.1, 23.0.0, 23.0.1, 24.0.0, 25.0.0