oss-sec mailing list archives
Re: [Openstack] [Openstack-announce] [OSSA 2012-014] Revoking a role does not affect existing tokens (CVE-2012-4413)
From: Russell Bryant <rbryant () redhat com>
Date: Wed, 12 Sep 2012 13:37:00 -0400
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 09/12/2012 01:07 PM, Matt Joyce wrote:
This is not a repeat of cve-2012-3426?
It's related, but not the same. That CVE did not include this specific issue (existing tokens including roles that may have since been revoked). It was for some other problems around token expiration, though. For reference: https://lists.launchpad.net/openstack/msg15164.html - -- Russell Bryant -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://www.enigmail.net/ iEYEARECAAYFAlBQyDwACgkQFg9ft4s9SAYVGgCfcQuY/uk4HlXh9ToPqqSPl7Nf h6kAoK/ZUqvTeHSkPbWyi1Y8+PEkt4tD =Cz/+ -----END PGP SIGNATURE-----
Current thread:
- [OSSA 2012-014] Revoking a role does not affect existing tokens (CVE-2012-4413) Thierry Carrez (Sep 12)
- Re: [Openstack-announce] [OSSA 2012-014] Revoking a role does not affect existing tokens (CVE-2012-4413) Matt Joyce (Sep 12)
- Re: Re: [Openstack-announce] [OSSA 2012-014] Revoking a role does not affect existing tokens (CVE-2012-4413) Kurt Seifried (Sep 12)
- Re: [Openstack] [Openstack-announce] [OSSA 2012-014] Revoking a role does not affect existing tokens (CVE-2012-4413) Russell Bryant (Sep 12)
- Re: [Openstack] [OSSA 2012-014] Revoking a role does not affect existing tokens (CVE-2012-4413) Soren Hansen (Sep 12)
- Re: [Openstack] [OSSA 2012-014] Revoking a role does not affect existing tokens (CVE-2012-4413) Dolph Mathews (Sep 12)
- Re: [Openstack-announce] [OSSA 2012-014] Revoking a role does not affect existing tokens (CVE-2012-4413) Matt Joyce (Sep 12)