CVE-2016-4911: Medium severity openstack keystone vulnerability
Published Jun 13, 2016
·Updated
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
Affected Software
4 affected componentsFixes available
pip/keystone>=9.0.0<9.0.1
9.0.1
Keystone OpenStack Identity=9.0.0.0-rc1
Keystone OpenStack Identity=9.0.0.0-rc2
Keystone OpenStack Identity=9.0.0.0-rc3
Remediation
Patch Available
Event History
Jun 13, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·03:41 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-4911?
CVE-2016-4911 is rated as important due to its potential to allow unauthorized access.
2
How do I fix CVE-2016-4911?
To fix CVE-2016-4911, upgrade to OpenStack Identity (Keystone) version 9.0.1 or later.
3
What impact does CVE-2016-4911 have on my system?
CVE-2016-4911 allows remote authenticated users to maintain access privileges by preventing token revocation.
4
Which versions of OpenStack are affected by CVE-2016-4911?
CVE-2016-4911 affects OpenStack Keystone versions before 9.0.1, including 9.0.0.0-rc1, 9.0.0.0-rc2, and 9.0.0.0-rc3.
5
Is there a known exploit for CVE-2016-4911?
Yes, CVE-2016-4911 can be exploited by authenticated users to bypass intended access restrictions.