MEDIUM 6.5 PyPI

OpenStack Identity (Keystone) UUID v2 tokens does not expire with revocation events

GHSA-v8fq-gq9j-3v7h · CVE-2014-5252 · PYSEC-2014-108

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a verification (1) GET or (2) HEAD request to v3/auth/tokens/.

Ready to move

Start Securing

Free, no credit card | First findings in minutes