|
|
| |
|
| |
openstack-keystone: delayed token invalidation
| Package(s): | keystone |
CVE #(s): | CVE-2013-2059
|
| Created: | May 17, 2013 |
Updated: | June 11, 2013 |
| Description: |
From the Ubuntu advisory:
Sam Stoelinga discovered that Keystone would not immediately invalidate
tokens when deleting users via the v2 API. A deleted user would be able to
continue to use resources until the token lifetime expired. |
| Alerts: |
|
( Log in to post comments)
|
|
|