Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 PyPI

OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend

GHSA-23x9-8hxr-978c · CVE-2014-2237 · PYSEC-2014-105

Published · Modified

Description

The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions.

Ready to move

Start Securing

Free, no credit card | First findings in minutes