OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-05-21 11:55
Updated : 2017-08-28 18:33
NVD link : CVE-2013-2059
Mitre link : CVE-2013-2059
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
openstack
- keystone