6.6

CVE-2022-2447

Exploit
A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openstack ≫ Keystone Version -
   Redhat ≫ Openstack Version 16.1
   Redhat ≫ Openstack Version 16.2 Update -
Redhat ≫ Openstack Platform Version 16.1
Redhat ≫ Openstack Platform Version 16.2
Redhat ≫ Quay Version 3.0.0
Redhat ≫ Storage Version 3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.62% 0.463
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.6 0.7 5.9
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-324 Use of a Key Past its Expiration Date

The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.

CWE-672 Operation on a Resource after Expiration or Release

The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.

https://access.redhat.com/security/cve/CVE-2022-2447
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2105419
Vendor Advisory
Exploit
Issue Tracking