Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenStack Keystone Token Expiration 多个安全绕过漏洞
Vulnerability Description
OpenStack Keystone 2012.1.1之前版本中存在多个安全绕过漏洞。已认证的攻击者可利用该漏洞绕过某些目地安全限制并获取对账户的扩展访问。
CVSS Information
N/A
Vulnerability Type
N/A