![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2013-4294 |
Description: | The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass intended access restrictions via a revoked PKI token. |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2013-4294 54706 http://secunia.com/advisories/54706 97237 http://osvdb.org/97237 RHSA-2013:1285 http://rhn.redhat.com/errata/RHSA-2013-1285.html USN-2002-1 http://www.ubuntu.com/usn/USN-2002-1 [oss-security] 20130911 [OSSA 2013-025] Token revocation failure using Keystone memcache/KVS backends (CVE-2013-4294) http://seclists.org/oss-sec/2013/q3/586 https://bugs.launchpad.net/keystone/+bug/1202952 https://bugs.launchpad.net/keystone/+bug/1202952 |