CVE-2013-1865

OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openstack:folsom:2012.2:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*

History

13 Feb 2023, 00:28

Type Values Removed Values Added
Summary CVE-2013-1865 OpenStack keystone: online validation of Keystone PKI tokens bypasses revocation check OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2013:0708', 'name': 'https://access.redhat.com/errata/RHSA-2013:0708', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=922230', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=922230', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2013-1865', 'name': 'https://access.redhat.com/security/cve/CVE-2013-1865', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 16:15

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/errata/RHSA-2013:0708 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=922230 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2013-1865 -
Summary OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token. CVE-2013-1865 OpenStack keystone: online validation of Keystone PKI tokens bypasses revocation check

Information

Published : 2013-03-22 21:55

Updated : 2023-12-10 11:16


NVD link : CVE-2013-1865

Mitre link : CVE-2013-1865

CVE.ORG link : CVE-2013-1865


JSON object : View

Products Affected

canonical

  • ubuntu_linux

openstack

  • folsom
CWE
CWE-287

Improper Authentication