PT-2012-6031 · Openstack · Openstack Keystone
Vijaya Erukala
·
Publicado
2012-12-18
·
Atualizado
2022-05-17
·
CVE-2012-5571
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Keystone versions 2012.1 through 2012.2
Description
The issue allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for a removed user role, due to improper handling of EC2 tokens when the user role has been removed from a tenant.
Recommendations
For versions 2012.1 and 2012.2, consider restricting access to EC2 tokens for removed user roles until a proper fix is applied. As a temporary workaround, review and manually revoke tokens for user roles that have been removed from a tenant to minimize the risk of exploitation.
Correção
IDOR
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openstack Keystone