Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Vijaya Erukala

#47383de 53,638
5.4CVSS total
Vulnerabilidades · 1
PT-2012-6031
5.4
2012-12-18
Openstack · Openstack Keystone · CVE-2012-5571
**Name of the Vulnerable Software and Affected Versions** OpenStack Keystone versions 2012.1 through 2012.2 **Description** The issue allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for a removed user role, due to improper handling of EC2 tokens when the user role has been removed from a tenant. **Recommendations** For versions 2012.1 and 2012.2, consider restricting access to EC2 tokens for removed user roles until a proper fix is applied. As a temporary workaround, review and manually revoke tokens for user roles that have been removed from a tenant to minimize the risk of exploitation.