Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenStack Keystone 信任管理问题漏洞
Vulnerability Description
OpenStack是美国美国国家航空航天局(NASA)的一个云平台管理项目。OpenStack Keystone是使用在OpenStack中的一个用于管理身份验证、服务规则和服务令牌功能的模块。 OpenStack Keystone 2013.1及之前的版本存在信任管理问题漏洞,该漏洞源于在用户被禁用的情况下,程序没有正确地撤销用户令牌。远程认证攻击者可借助此令牌利用该漏洞继续访问云空间。
CVSS Information
N/A
Vulnerability Type
N/A