CVE-2016-4911

medium
Published 2016-06-13 · Modified 2024-11-25
CVSS v3
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v4 NEW
not yet in upstream
VIR risk
4.3

Description

The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.

Predictions

Exploit likelihood
53%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2016-4911 NameCVE-2016-4911 DescriptionThe Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub…

CVE-2016-4911

NameCVE-2016-4911
DescriptionThe Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs824683

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
keystone (PTS)bullseye2:18.0.0-3+deb11u1fixed
bullseye (security)2:18.1.0-1+deb11u3fixed
bookworm, bookworm (security)2:22.0.2-0+deb12u1fixed
trixie (security), trixie2:27.0.0-3+deb13u1fixed
forky, sid2:29.0.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
keystonesourcewheezy(not affected)
keystonesourcejessie(not affected)
keystonesource(unstable)2:9.0.0-2824683

Notes

[jessie] - keystone <not-affected> (affects only 9.0.0)
[wheezy] - keystone <not-affected> (affects only 9.0.0)
https://launchpad.net/bugs/1577558

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[jessie] - keystone <not-affected> (affects only 9.0.0)[wheezy] - keystone <not-affected> (affects only 9.0.0)https://launchpad.net/bugs/1577558

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2:9.0.0-2
sid Fixed 2:9.0.0-2
forky Fixed 2:9.0.0-2
bullseye Fixed 2:9.0.0-2
bookworm Fixed 2:9.0.0-2

Package impact

EcosystemPackageVulnerableFixed
python PyPIkeystone>=9.0.0,<9.0.19.0.1

Application impact

VendorProductVersionsFixed
keystoneopenstack_identity9.0.0.0

References

CWEs

CWE-284

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.