CVE-2015-7546

Description

The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly invalidate authorization tokens when using the PKI or PKIZ token providers, which allows remote authenticated users to bypass intended access restrictions and gain access to cloud resources by manipulating byte fields within a revoked token.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.105

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2015-7546 are fixed in Python-keystonemiddleware 1.5.4Windows
Vulnerabilities CVE-2015-7546 are fixed in Python-keystonemiddleware 2.3.3Windows
Vulnerabilities CVE-2015-7546 are fixed in Python-keystonemiddleware 4.1.0Windows
Vulnerabilities CVE-2015-7546 are fixed in Python-keystonemiddleware for linux 1.5.4Linux
Vulnerabilities CVE-2015-7546 are fixed in Python-keystonemiddleware for linux 2.3.3Linux
Vulnerabilities CVE-2015-7546 are fixed in Python-keystonemiddleware for linux 4.1.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234