CVE-2015-7546

EUVD-2016-0013
The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly invalidate authorization tokens when using the PKI or PKIZ token providers, which allows remote authenticated users to bypass intended access restrictions and gain access to cloud resources by manipulating byte fields within a revoked token.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 28%
Affected Products (NVD)
VendorProductVersion
openstackkeystonemiddleware
1.5.0 ≤
𝑥
≤ 1.5.3
openstackkeystonemiddleware
1.6.0 ≤
𝑥
≤ 2.3.2
openstackkeystone
8.0.0 ≤
𝑥
< 8.0.2
openstackkeystone
2015.1.0 ≤
𝑥
≤ 2015.1.2
oraclesolaris
11.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
keystone
bookworm
2:22.0.0-2
fixed
bullseye
2:18.0.0-3+deb11u1
fixed
jessie
no-dsa
sid
2:26.0.0-1
fixed
trixie
2:26.0.0-1
fixed
wheezy
no-dsa
python-keystonemiddleware
bookworm
10.1.0-4
fixed
bullseye
9.1.0-2
fixed
jessie
no-dsa
sid
10.7.1-2
fixed
trixie
10.7.1-2
fixed
wheezy
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
keystone
precise
ignored
trusty
dne
vivid
ignored
wily
not-affected
xenial
not-affected
yakkety
not-affected
zesty
not-affected
python-keystonemiddleware
precise
dne
trusty
dne
vivid
ignored
wily
ignored
xenial
not-affected
yakkety
not-affected
zesty
not-affected