OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3...
Moderate severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 10, 2023
Description
Published by the National Vulnerability Database
Sep 30, 2013
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 10, 2023
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
References