CVE-2014-2237

OpenStack Identity (Keystone) - Info Disclosure

Title source: llm

Description

The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions.

Scores

EPSS 0.0019
EPSS Percentile 40.5%

Classification

CWE
CWE-264
Status draft

Affected Products (7)

openstack/keystone
openstack/keystone
openstack/keystone
openstack/keystone
openstack/keystone
openstack/keystone
pypi/keystone < 8.0.0a0PyPI

Timeline

Published Apr 01, 2014
Tracked Since Feb 18, 2026