Comment 26 for bug 1166670

Revision history for this message
Thierry Carrez (ttx) wrote : Re: Deleted user can still create instances

Here is proposed impact description, please doublecheck.

@Sam, do you want us to credit a specific company for the discovery, in addition to your name ?

================================================
Title: Keystone tokens not immediately invalidated when user is deleted
Reporter: Sam Stoelinga
Products: Keystone
Affects: All versions

Description:
Sam Stoelinga reported a vulnerability in Keystone. When users are deleted through Keystone v2 API, existing tokens for those users are not immediately invalidated and remain valid for the duration of the token's life (by default, up to 24 hours). This may result in users retaining access when the administrator of the system thought them disabled. Keystone setups using the v3 API call to delete users are unaffected. You can workaround this issue by disabling a user before deleting it: in that case the tokens belonging to the disabled user are immediately invalidated.
================================================