CVE-2015-7546

The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly invalidate authorization tokens when using the PKI or PKIZ token providers, which allows remote authenticated users to bypass intended access restrictions and gain access to cloud resources by manipulating byte fields within a revoked token.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
VendorProductVersion
openstackkeystonemiddleware
1.5.0 ≤
𝑥
≤ 1.5.3
openstackkeystonemiddleware
1.6.0 ≤
𝑥
≤ 2.3.2
openstackkeystone
8.0.0 ≤
𝑥
< 8.0.2
openstackkeystone
2015.1.0 ≤
𝑥
≤ 2015.1.2
oraclesolaris
11.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
keystone
bullseye
2:18.0.0-3+deb11u1
fixed
jessie
no-dsa
wheezy
no-dsa
bookworm
2:22.0.0-2
fixed
sid
2:26.0.0-1
fixed
trixie
2:26.0.0-1
fixed
python-keystonemiddleware
bullseye
9.1.0-2
fixed
jessie
no-dsa
wheezy
no-dsa
bookworm
10.1.0-4
fixed
sid
10.7.1-2
fixed
trixie
10.7.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
keystone
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
ignored
trusty
dne
precise
ignored
python-keystonemiddleware
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
ignored
vivid
ignored
trusty
dne
precise
dne