CVE-2014-2237
OpenStack Identity (Keystone) - Info Disclosure
Title source: llmDescription
The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions.
Scores
EPSS
0.0019
EPSS Percentile
40.5%
Classification
CWE
CWE-264
Status
draft
Affected Products (7)
openstack/keystone
openstack/keystone
openstack/keystone
openstack/keystone
openstack/keystone
openstack/keystone
pypi/keystone
< 8.0.0a0PyPI
Timeline
Published
Apr 01, 2014
Tracked Since
Feb 18, 2026