4
CVSSv2

CVE-2012-4457

Published: 09/10/2012 Updated: 16/11/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

OpenStack Keystone Essex prior to 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack keystone

openstack keystone 2012.2

Vendor Advisories

Synopsis Important: openstack-keystone security update Type/Severity Security Advisory: Important Topic Updated openstack-keystone packages that fix multiple security issues arenow available for Red Hat OpenStack EssexThe Red Hat Security Response Team has rated this update as havingimportant security impa ...
Debian Bug report logs - #689210 keystone: CVE-2012-445{6,7} Package: keystone; Maintainer for keystone is Debian OpenStack <team+openstack@trackerdebianorg>; Source for keystone is src:keystone (PTS, buildd, popcon) Reported by: Yves-Alexis Perez <corsac@debianorg> Date: Sun, 30 Sep 2012 12:09:01 UTC Severity: g ...