4.3

CVE-2016-4911

The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KeystoneOpenstack Identity Version9.0.0.0 Updaterc1
KeystoneOpenstack Identity Version9.0.0.0 Updaterc2
KeystoneOpenstack Identity Version9.0.0.0 Updaterc3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.4% 0.69
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

http://www.openwall.com/lists/oss-security/2016/05/17/10
Mailing List
http://www.openwall.com/lists/oss-security/2016/05/17/11
Mailing List
http://www.securityfocus.com/bid/90728
Third Party Advisory
VDB Entry
https://bugs.launchpad.net/keystone/+bug/1577558
Vendor Advisory
https://review.openstack.org/#/c/311886/
Vendor Advisory
https://security.openstack.org/ossa/OSSA-2016-008.html
Patch
Vendor Advisory