PublicDateAtUSN: 2014-08-15 Candidate: CVE-2014-5253 PublicDate: 2014-08-25 14:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5253 https://launchpad.net/bugs/1349597 https://git.openstack.org/cgit/openstack/keystone/commit/?id=317f9d34b4da20c21edd5b851889298b67c843e1 https://ubuntu.com/security/notices/USN-2324-1 Description: OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domain. Ubuntu-Description: Notes: jdstrand> Per upstream, revocation events added in Icehouse (Ubuntu 14.04 LTS) Bugs: Priority: medium Discovered-by: Brant Knudson Assigned-to: jdstrand CVSS: Patches_keystone: upstream: https://review.openstack.org/112084 (icehouse) upstream: https://review.openstack.org/109820 (juno) upstream_keystone: released (2014.1.2.1-1) lucid_keystone: DNE precise_keystone: not-affected trusty_keystone: released (1:2014.1.2.1-0ubuntu1.1) trusty/esm_keystone: DNE (trusty was released [1:2014.1.2.1-0ubuntu1.1]) devel_keystone: not-affected (1:2014.2~b3-0ubuntu1)