7.5
CVSSv2

CVE-2012-4456

Published: 09/10/2012 Updated: 13/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex prior to 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote malicious users to read the roles for an arbitrary user or get, create, or delete arbitrary services.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack keystone 2012.2

openstack keystone

Vendor Advisories

Synopsis Important: openstack-keystone security update Type/Severity Security Advisory: Important Topic Updated openstack-keystone packages that fix multiple security issues arenow available for Red Hat OpenStack EssexThe Red Hat Security Response Team has rated this update as havingimportant security impa ...
Debian Bug report logs - #689210 keystone: CVE-2012-445{6,7} Package: keystone; Maintainer for keystone is Debian OpenStack <team+openstack@trackerdebianorg>; Source for keystone is src:keystone (PTS, buildd, popcon) Reported by: Yves-Alexis Perez <corsac@debianorg> Date: Sun, 30 Sep 2012 12:09:01 UTC Severity: g ...