SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-5251

The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to…

MEDIUM 4.9EPSS 1.59%

Does this matter?

Lower severity and a low EPSS score (1.59%). Track it; it rarely justifies an emergency change on its own.

Description

The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.

CVSS 2.0
4.9 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
EPSS
1.59% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-255
Affected
openstack/keystone · canonical/ubuntu linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.