Please review this vulnerability description.  Once confirmed, it will
go out in an OSSA.


Title: Token authorization for a user in a disabled tenant is allowed
Impact: High
Reporter: Rohit Karajgi (NTT Data)
Affects: Essex (prior to 2012.1.2), Folsom (prior to folsom-3 development 
milestone)

Description:
Rohit Karajgi reported a vulnerability in Keystone. It was possible to get a 
token that is authorized for a disabled tenant. Once the token is established 
with authorization on the tenant, keystone would respond 200 OK to token 
validation requests from other OpenStack services, allowing the user to work 
with the tenant's resources.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/988920

Title:
  Token authentication for a user in a disabled tenant does not raise
  Unauthorized error

To manage notifications about this bug go to:
https://bugs.launchpad.net/keystone/+bug/988920/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to