—
PYSEC-2014-109
Quick fix
PYSEC-2014-109 — keystone: upgrade to the fixed version with the command below.
pip install --upgrade 'keystone>=8.0.0a0'Details
OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domain.
Are you affected?
Enter the version of the package you're using.