Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass intended access restrictions via a revoked PKI token.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenStack Identity Folsom 权限许可和访问控制问题漏洞
Vulnerability Description
OpenStack是美国美国国家航空航天局(NASA)的一个云平台管理项目。OpenStack Keystone是使用在OpenStack中的一个用于管理身份验证、服务规则和服务令牌功能的模块。 OpenStack Identity (Keystone) Folsom 2012.2.x版本和Grizzly 2013.1.4之前版本存在权限许可和访问控制问题漏洞,该漏洞源于PKI令牌撤销列表存储整个令牌,而不是令牌ID,导致撤销的PKI令牌仍视为有效。远程攻击者利用该漏洞绕过既定的访问限制。
CVSS Information
N/A
Vulnerability Type
N/A