OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2013-05-21 18:55
Updated : 2025-04-11 00:51
NVD link : CVE-2013-2059
Mitre link : CVE-2013-2059
CVE.ORG link : CVE-2013-2059
JSON object : View
Products Affected
openstack
- keystone
CWE
CWE-287
Improper Authentication