MEDIUM 4.3 PyPI
OpenStack Identity Keystone Improper Access Control
GHSA-f82m-w3p3-cgp3 · CVE-2016-4911 · PYSEC-2016-38
Published · Modified
Description
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2016-4911
- WEB https://github.com/openstack/keystone/commit/0d376025bae61bf5ee19d992c7f336b99ac69240
- WEB https://github.com/openstack/keystone/commit/ee1dc941042d1f71699971c5c30566af1b348572
- WEB https://bugs.launchpad.net/keystone/+bug/1577558
- PACKAGE https://github.com/openstack/keystone
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/keystone/PYSEC-2016-38.yaml
- WEB https://review.openstack.org/#/c/311886
- WEB https://security.openstack.org/ossa/OSSA-2016-008.html
- WEB http://www.openwall.com/lists/oss-security/2016/05/17/10
- WEB http://www.openwall.com/lists/oss-security/2016/05/17/11
Ready to move
Start Securing
Free, no credit card | First findings in minutes