A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.
{
"priority_reason": "Upstream keystone developers have rated this to be a low severity issue",
"binaries": [
{
"binary_version": "2:17.0.1-0ubuntu2",
"binary_name": "keystone"
},
{
"binary_version": "2:17.0.1-0ubuntu2",
"binary_name": "keystone-common"
},
{
"binary_version": "2:17.0.1-0ubuntu2",
"binary_name": "python3-keystone"
}
]
}
{
"priority_reason": "Upstream keystone developers have rated this to be a low severity issue",
"availability": "No subscription required",
"binaries": [
{
"binary_version": "2:21.0.1-0ubuntu2.1",
"binary_name": "keystone"
},
{
"binary_version": "2:21.0.1-0ubuntu2.1",
"binary_name": "keystone-common"
},
{
"binary_version": "2:21.0.1-0ubuntu2.1",
"binary_name": "python3-keystone"
}
]
}