python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.
{
"github_reviewed": true,
"severity": "HIGH",
"nvd_published_at": "2014-01-21T18:55:00Z",
"cwe_ids": [
"CWE-324"
],
"github_reviewed_at": "2023-08-29T18:28:22Z"
}