|
|
| |
|
| |
python-keystoneclient: PKI token expiration botch
| Package(s): | python-keystoneclient |
CVE #(s): | CVE-2013-2104
|
| Created: | June 4, 2013 |
Updated: | August 12, 2013 |
| Description: |
From the Ubuntu advisory:
Eoghan Glynn and Alex Meade discovered that python-keystoneclient did not
properly perform expiry checks for the PKI tokens used in Keystone. If
Keystone were setup to use PKI tokens (the default in Ubuntu 13.04), a
previously authenticated user could continue to use a PKI token for longer
than intended. |
| Alerts: |
|
( Log in to post comments)
|
|
|