CVE-2015-7546

HIGH

OpenStack Identity <2015.1.3-8.0.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly invalidate authorization tokens when using the PKI or PKIZ token providers, which allows remote authenticated users to bypass intended access restrictions and gain access to cloud resources by manipulating byte fields within a revoked token.

References (5)

Core 5
Core References
Vendor Advisory x_refsource_confirm
https://wiki.openstack.org/wiki/OSSN/OSSN-0062
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugs.launchpad.net/keystone/+bug/1490804
Patch, Vendor Advisory x_refsource_confirm
https://security.openstack.org/ossa/OSSA-2016-005.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/80498

Scores

CVSS v3 7.5
EPSS 0.0010
EPSS Percentile 28.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-522
Status published
Products (5)
openstack/keystone 8.0.0 - 8.0.2
openstack/keystonemiddleware 1.5.0 - 1.5.3
oracle/solaris 11.3
pypi/keystone 9.0.0.0b1 - 9.0.0.0b2PyPI
pypi/keystonemiddleware 2.4.0 - 4.1.0PyPI
Published Feb 03, 2016
Tracked Since Feb 18, 2026