UNKNOWN OpenStack

CVE-2015-7546

OSSN-0062: = Potential reuse of revoked Identity tokens =

An authorization token issued by the Identity service can be revoked, which is designed to immediately make that token invalid for future use. When the PKI or PKIZ token providers are used, it is possible for an attacker to manipulate the token contents of a revoked token such that the token will still be considered to be valid. This can allow unauthorized access to cloud resources if a revoked token is intercepted by an attacker.

Affected Products

References

Published: 2026-08-27 · Source: OpenStack · Feed updated: 2026-08-27
This unknown severity vulnerability was published on 2026-08-27 via OpenStack. Affected: CVE-2015-7546.
vulnfeed aggregates 11337 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.