CVE-2016-4911
13.06.2016, 14:59
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.Enginsight
Vendor | Product | Version |
---|---|---|
keystone | openstack_identity | 9.0.0.0:rc1 |
keystone | openstack_identity | 9.0.0.0:rc2 |
keystone | openstack_identity | 9.0.0.0:rc3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References