Comment 0 for bug 1050025

Revision history for this message
Russell Bryant (russellb) wrote : Potential problem with fix for "Revoking a role does not affect existing tokens (CVE-2012-4413)"

We just released this security advisory:

    https://lists.launchpad.net/openstack/msg16659.html

Soren Hansen brought up a potential problem here:

    https://lists.launchpad.net/openstack/msg16662.html

I'm filing it as a bug to ensure it gets reviewed and addressed.