From ${URL} : A vulnerability was found in the Keystone Fernet Token Provider. By rescoping a token a user will receive a new token without correct audit_ids, these incorrect audit_ids will prevent the entire chain of tokens from being revoked properly. This vulnerability does not impact revoking a token by it's individual audit_id. Only deployments with Keystone configured to use Fernet tokens are impacted. References: http://seclists.org/oss-sec/2016/q2/358 https://bugs.launchpad.net/keystone/+bug/1577558 @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
I've confirmed that <keystone-9 is not impacted by this bug. I've patched and removed the badness, removing myself/project as we are completed here.
Closing as noglsa.