关键漏洞信息 漏洞描述 漏洞编号: OSSA 2013-014 漏洞类型: auth_token middleware neglects to check expiry of signed token 影响的组件和版本: - OpenStack Identity (keystone): Invalid, Folsom release fixed, Critical impact - OpenStack Security Advisory - python-keystoneclient: Fix Released, Critical impact 漏洞细节 问题: The auth_token middleware in Keystone ignores the expiry of signed tokens. It only checks if the token has been explicitly revoked. 参考链接: - Code snippet: https://github.com/openstack/python-keystoneclient/blob/master/keystoneclient/middleware/auth_token.py#L1047 相关分支 lp:ubunturaring-security/python-keystoneclient lp:ubuntu/quantal-security/keystone lp:ubuntu/quantal-updates/keystone CVE 参考 CVE-2013-2104 关键讨论点 确认修复patch是否解决了问题 影响范围主要是PKI tokens的认证验证问题 对于不同版本的维护和修复讨论 状态更新 Bug最终被标记为 🔥影响状态更新为 进度更新和分配人员记录显示了对修复过程的跟踪和讨论