4.9
CVSSv2

CVE-2012-3426

Published: 31/07/2012 Updated: 07/09/2012
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

OpenStack Keystone prior to 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack essex

openstack keystone 2012.1.1

openstack keystone 2012.1

openstack horizon folsom-1

Vendor Advisories

Keystone would allow unintended access to files over the network ...
Two security issues were fixed in OpenStack Keystone ...