Total vulnerabilities in the database
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
Software | From | Fixed in |
---|---|---|
openstack / keystone | 2013.1 | 2013.1.3.x |
fedoraproject / fedora | 20 | 20.x |
canonical / ubuntu_linux | 13.04 | 13.04.x |
canonical / ubuntu_linux | 12.10 | 12.10.x |
redhat / openstack | 3.0 | 3.0.x |