CVE-2022-2447

A flaw was found in OpenStack. The application credential tokens can be used even after they have expired. This flaw allows an authenticated remote attacker to obtain access despite the defender's efforts to remove access.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:openstack:keystone:-:*:*:*:*:*:*:*
OR cpe:2.3:a:redhat:openstack:16.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:16.2:-:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:openstack_platform:16.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack_platform:16.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:storage:3.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:01

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2022-2447 - Vendor Advisory () https://access.redhat.com/security/cve/CVE-2022-2447 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2105419 - Exploit, Issue Tracking, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=2105419 - Exploit, Issue Tracking, Vendor Advisory

14 Sep 2022, 17:48

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 7.2

07 Sep 2022, 18:27

Type Values Removed Values Added
CWE CWE-672
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
References (MISC) https://access.redhat.com/security/cve/CVE-2022-2447 - (MISC) https://access.redhat.com/security/cve/CVE-2022-2447 - Vendor Advisory
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2105419 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2105419 - Exploit, Issue Tracking, Vendor Advisory
CPE cpe:2.3:a:redhat:openstack:16.2:-:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:16.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:storage:3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack_platform:16.1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack_platform:16.2:*:*:*:*:*:*:*

02 Sep 2022, 12:56

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-01 21:15

Updated : 2024-11-21 07:01


NVD link : CVE-2022-2447

Mitre link : CVE-2022-2447

CVE.ORG link : CVE-2022-2447


JSON object : View

Products Affected

redhat

  • quay
  • openstack_platform
  • openstack
  • storage

openstack

  • keystone
CWE
CWE-324

Use of a Key Past its Expiration Date

CWE-672

Operation on a Resource after Expiration or Release