-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| keystone | pip | < 2012.1.3 | 2012.1.3 |
The vulnerability stemmed from Keystone's failure to revoke tokens during role changes. The patches add token revocation calls to four role management methods in identity/core.py. These functions in their original form (without revocation) would appear in profilers when attackers exploit stale tokens after role changes. The direct modification evidence in all four functions indicates they were the missing security controls.
Ongoing coverage of React2Shell