The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.
{
"nvd_published_at": "2014-08-25T14:55:00Z",
"cwe_ids": [
"CWE-613"
],
"severity": "HIGH",
"github_reviewed_at": "2024-05-14T21:16:54Z",
"github_reviewed": true
}