OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://osvdb.org/85484 | vdb entry |
http://secunia.com/advisories/50531 | third party advisory vendor advisory |
http://www.openwall.com/lists/oss-security/2012/09/12/7 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/78478 | vdb entry |
http://www.ubuntu.com/usn/USN-1564-1 | vendor advisory |
http://www.securityfocus.com/bid/55524 | vdb entry |
http://secunia.com/advisories/50590 | third party advisory vendor advisory |