CVE-2015-7546

HIGH

OpenStack Identity <2015.1.3-8.0.2 - Privilege Escalation

Title source: llm

Description

The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly invalidate authorization tokens when using the PKI or PKIZ token providers, which allows remote authenticated users to bypass intended access restrictions and gain access to cloud resources by manipulating byte fields within a revoked token.

Scores

CVSS v3 7.5
EPSS 0.0010
EPSS Percentile 28.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-522
Status draft

Affected Products (5)

openstack/keystonemiddleware < 1.5.3
openstack/keystone < 8.0.2
oracle/solaris
pypi/keystone < 9.0.0.0b2PyPI
pypi/keystonemiddleware < 4.1.0PyPI

Timeline

Published Feb 03, 2016
Tracked Since Feb 18, 2026