4.9
CVSSv2

CVE-2014-5251

Published: 25/08/2014 Updated: 10/10/2014
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x prior to 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack keystone juno-2

openstack keystone 2014.1

canonical ubuntu linux 14.04

openstack keystone juno-1

openstack keystone 2014.1.2

Vendor Advisories

Several security issues were fixed in OpenStack Keystone ...