CVE-2013-4222
EUVD-2013-412630.09.2013, 22:55
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openstack | keystone | 2013.1 ≤ 𝑥 ≤ 2013.1.3 |
| canonical | ubuntu_linux | 12.10 |
| canonical | ubuntu_linux | 13.04 |
| redhat | openstack | 3.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References