CVE-2016-4911
13.06.2016, 14:59
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.Enginsight
| Vendor | Product | Version |
|---|---|---|
| keystone | openstack_identity | 9.0.0.0:rc1 |
| keystone | openstack_identity | 9.0.0.0:rc2 |
| keystone | openstack_identity | 9.0.0.0:rc3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References