VDB
Sign up

PYSEC-2012-35

Withdrawn 2024-11-22. This finding no longer applies and is kept for reference. It is not used when checking packages.

Quick fix

PYSEC-2012-35 — keystone: upgrade to the fixed version with the command below.

pip install --upgrade 'keystone>=37308dd4f3e33f7bd0f71d83fd51734d1870713b'

Details

OpenStack Keystone Essex (2012.1) and Folsom (2012.2) does not properly handle EC2 tokens when the user role has been removed from a tenant, which allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for the removed user role.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/keystone
Introduced in: 0Fixed in: 37308dd4f3e33f7bd0f71d83fd51734d1870713b
Fixpip install --upgrade 'keystone>=37308dd4f3e33f7bd0f71d83fd51734d1870713b'

References