CVE-2014-5251: Medium severity keystone vulnerability
The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5251?
CVE-2014-5251 is considered a medium severity vulnerability due to its potential for abuse by authenticated users.
How do I fix CVE-2014-5251?
To fix CVE-2014-5251, upgrade OpenStack Keystone to version 2014.1.2.1 or newer, or Juno to Juno-3 or later.
What is the impact of CVE-2014-5251?
The impact of CVE-2014-5251 allows remote authenticated users to retain access to resources using expired tokens due to incorrect timestamp handling.
Which versions of OpenStack Keystone are affected by CVE-2014-5251?
OpenStack Keystone versions 2014.1.x before 2014.1.2.1 and Juno before Juno-3 are affected by CVE-2014-5251.
Who can exploit CVE-2014-5251?
CVE-2014-5251 can be exploited by remote authenticated users who have access to tokens in the affected OpenStack Keystone versions.