First published: Fri Mar 15 2013(Updated: )
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Folsom | =2012.2 | |
Canonical Ubuntu Linux | =12.10 | |
pip/keystone | >=2012.2<2012.2.4 | 2012.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.