4.3
CVSSv2

CVE-2012-3542

Published: 05/09/2012 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote malicious users to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack essex 2012.1

openstack horizon folsom-3

Vendor Advisories

Synopsis Important: openstack-keystone security update Type/Severity Security Advisory: Important Topic Updated openstack-keystone packages that fix multiple security issues arenow available for Red Hat OpenStack EssexThe Red Hat Security Response Team has rated this update as havingimportant security impa ...
Two security issues were fixed in OpenStack Keystone ...