Information on source package keystone

Available versions

ReleaseVersion
jessie2014.1.3-6
stretch2:10.0.0-9
stretch (security)2:10.0.0-9+deb9u1
buster2:13.0.0-7
sid2:13.0.0-7

Open issues

BugjessiestretchbustersidDescription
CVE-2018-14432vulnerablefixedfixedfixedIn the Federation component of OpenStack Keystone before 11.0.4, ...
CVE-2015-7546vulnerable (no DSA)fixedfixedfixedThe identity service in OpenStack Identity (Keystone) before 2015.1.3 ...
CVE-2015-3646vulnerable (no DSA)fixedfixedfixedOpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before ...

Resolved issues

BugDescription
CVE-2017-2673An authorization-check flaw was discovered in federation ...
CVE-2016-4911The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x ...
CVE-2014-5253OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno ...
CVE-2014-5252The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 ...
CVE-2014-5251The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x ...
CVE-2014-3621The catalog url replacement in OpenStack Identity (Keystone) before ...
CVE-2014-3520OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, ...
CVE-2014-3476OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, ...
CVE-2014-2828The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and ...
CVE-2014-2237The memcache token backend in OpenStack Identity (Keystone) 2013.1 ...
CVE-2014-0204OpenStack Identity (Keystone) before 2014.1.1 does not properly handle ...
CVE-2014-0105The auth_token middleware in the OpenStack Python client library for ...
CVE-2013-6391The ec2tokens API in OpenStack Identity (Keystone) before Havana ...
CVE-2013-4477The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, ...
CVE-2013-4294The (1) mamcache and (2) KVS token backends in OpenStack Identity ...
CVE-2013-4222OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, ...
CVE-2013-2255Inconsistent and non-validating HTTPS client
CVE-2013-2157OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when ...
CVE-2013-2104python-keystoneclient before 0.2.4, as used in OpenStack Keystone ...
CVE-2013-2059OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly ...
CVE-2013-2014OpenStack Identity (Keystone) before 2013.1 allows remote attackers to ...
CVE-2013-2006OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode ...
CVE-2013-1977OpenStack devstack uses world-readable permissions for keystone.conf, ...
CVE-2013-1865OpenStack Keystone Folsom (2012.2) does not properly perform ...
CVE-2013-1665The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used ...
CVE-2013-1664The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used ...
CVE-2013-0282OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, ...
CVE-2013-0270OpenStack Keystone Grizzly before 2013.1, Folsom, and possibly earlier ...
CVE-2013-0247OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and ...
CVE-2012-5571OpenStack Keystone Essex (2012.1) and Folsom (2012.2) does not ...
CVE-2012-5563OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not ...
CVE-2012-5483tools/sample_data.sh in OpenStack Keystone 2012.1.3, when access to ...
CVE-2012-4457OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 ...
CVE-2012-4456The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone ...
CVE-2012-4413OpenStack Keystone 2012.1.3 does not invalidate existing tokens when ...
CVE-2012-3542OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and ...
CVE-2012-3426OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before ...
CVE-2012-1572

Security announcements

DSA / DLADescription
DSA-4275-1keystone - security update

Search for package or bug name: Reporting problems