REDHAT-BUG-861180: Medium severity keystone vulnerability
Rohit Karajgi discovered a vulnerability in OpenStack Keystone token handling:
Token authentication for a user belonging to a disable tenant should not be allowed.
External References: https://bugs.launchpad.net/keystone/+bug/988920
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-861180?
The vulnerability REDHAT-BUG-861180 is classified as a critical issue due to improper token handling in OpenStack Keystone.
How do I fix REDHAT-BUG-861180?
To fix REDHAT-BUG-861180, ensure that user tokens for disabled tenants are not allowed in your OpenStack Keystone configuration.
What systems are affected by REDHAT-BUG-861180?
REDHAT-BUG-861180 affects OpenStack Keystone and its token authentication mechanisms.
Who discovered the vulnerability REDHAT-BUG-861180?
The vulnerability REDHAT-BUG-861180 was discovered by Rohit Karajgi.
What is the impact of the token handling issue in REDHAT-BUG-861180?
The impact of REDHAT-BUG-861180 means that users can authenticate using tokens from disabled tenants, potentially allowing unauthorized access.