Description:
Brant Knudson from IBM reported a vulnerability in Keystone revocation events. If a domain is invalidated and that generates a revocation event, that revocation event won't match domain-scoped tokens so those tokens won't be revoked. Only Keystone setups configured to use revocation events are affected.
Title: Domain-scoped tokens don't get revoked
Reporter: Brant Knudson (IBM)
Products: Keystone
Versions: 2014.1.1
Description:
Brant Knudson from IBM reported a vulnerability in Keystone revocation events. If a domain is invalidated and that generates a revocation event, that revocation event won't match domain-scoped tokens so those tokens won't be revoked. Only Keystone setups configured to use revocation events are affected.