QID 996740
Date Published: 2024-01-17
QID 996740: Python (Pip) Security Update for Keystone (GHSA-x8h4-xf47-pqc3)
OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-x8h4-xf47-pqc3 for updates and patch information.
Vendor References
- GHSA-x8h4-xf47-pqc3 -
github.com/advisories/GHSA-x8h4-xf47-pqc3
CVEs related to QID 996740
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x8h4-xf47-pqc3 | Keystone |
|