Description
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-0014 | OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token. |
Github GHSA |
GHSA-22q6-wwq7-2jj9 | OpenStack Keystone Improper Authentication vulnerability |
Ubuntu USN |
USN-1772-1 | OpenStack Keystone vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T15:20:37.275Z
Reserved: 2013-02-19T00:00:00.000Z
Link: CVE-2013-1865
No data.
Status : Modified
Published: 2013-03-22T21:55:01.510
Modified: 2026-04-29T01:13:23.040
Link: CVE-2013-1865
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN