Back

HIGH

openstack-keystone: revocation events are broken with mysql

Published Aug 25, 2014

Description

The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.

Affected products

Remediation

Red Hat statement

This issue does not affected openstack-keystone as shipped with Red Hat Enterprise Linux OpenStack Platform 4.0.

Metrics

Weaknesses (2)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 25, 2014
Updated Aug 6, 2024
Reserved Aug 15, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jul 23, 2014
GHSA-GMVP-5RF9-MXCM