VDB
KO
MEDIUM 4.3

PYSEC-2016-38

Details

The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / keystone
Introduced in: 9.0.0 Fixed in: 9.0.1
Fix pip install --upgrade 'keystone>=9.0.1'

References