LWN.net Logo

openstack-keystone: delayed token invalidation

Package(s):keystone CVE #(s):CVE-2013-2059
Created:May 17, 2013 Updated:June 11, 2013
Description:

From the Ubuntu advisory:

Sam Stoelinga discovered that Keystone would not immediately invalidate tokens when deleting users via the v2 API. A deleted user would be able to continue to use resources until the token lifetime expired.

Alerts:
Ubuntu USN-1830-1 2013-05-16
Fedora FEDORA-2013-8048 2013-05-22
openSUSE openSUSE-SU-2013:0949-1 2013-06-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds