CVE-2013-4222: Medium severity keystone vulnerability
Published Sep 30, 2013
·Updated
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
Affected Software
5 affected components
Openstack Keystone>=2013.1<=2013.1.3
Fedoraproject Fedora=20
Canonical Ubuntu Linux=12.10
Canonical Ubuntu Linux=13.04
redhat Openstack=3.0
Event History
Sep 30, 2013
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4222?
CVE-2013-4222 is considered a high-severity vulnerability due to its impact on authentication and access control.
2
How do I fix CVE-2013-4222?
To fix CVE-2013-4222, you should upgrade OpenStack Identity (Keystone) to version 2013.1.4 or later.
3
Which versions of OpenStack are affected by CVE-2013-4222?
CVE-2013-4222 affects OpenStack Identity (Keystone) versions 2013.1.3 and earlier.
4
What are the consequences of CVE-2013-4222?
CVE-2013-4222 can allow remote authenticated users to retain access to resources even after their tenant has been disabled.
5
Is there a workaround for CVE-2013-4222?
There is no official workaround for CVE-2013-4222; upgrading is the recommended approach.