The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://bugs.launchpad.net/keystone/+bug/1577558 | vendor advisory |
http://www.openwall.com/lists/oss-security/2016/05/17/10 | mailing list |
http://www.securityfocus.com/bid/90728 | third party advisory vdb entry |
https://security.openstack.org/ossa/OSSA-2016-008.html | patch vendor advisory |
https://review.openstack.org/#/c/311886/ | vendor advisory |
http://www.openwall.com/lists/oss-security/2016/05/17/11 | mailing list |