Release date:
Updated on: 2012-09-06
Affected Systems:
Ubuntu Linux 12.04 LTS i386
Ubuntu Linux 12.04 LTS amd64
Openstack Keystone
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54709
Cve id: CVE-2012-3426
OpenStack Keystone is a project that provides identity, Token, directory, and policy services for the OpenStack series.
OpenStack Keystone versions earlier than January 1, failed to correctly execute token expiration. You can use the token chain to Create a token, use the token used to disable the user account, and use the account with the changed password, remote authenticated users can bypass the target authentication restriction.
<* Source: Derek Higgins
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Openstack
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://horizon.openstack.org/intro.html