Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Dolph Mathews

Researcher fromRackspace
#20266of 53,632
12.7Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2012-5384
4.0
2012-09-18
Openstack · Openstack Keystone · CVE-2012-4413
**Name of the Vulnerable Software and Affected Versions** OpenStack Keystone versions prior to 2012.1.3 **Description** The issue allows remote authenticated users to retain the privileges of revoked roles because existing tokens are not invalidated when roles are granted or revoked. **Recommendations** For versions prior to 2012.1.3, update to version 2012.1.3 or later to ensure that existing tokens are properly invalidated when roles are granted or revoked.
PT-2012-4796
8.7
2012-09-05
Openstack · Openstack Keystone · CVE-2012-3542
**Name of the Vulnerable Software and Affected Versions** OpenStack Keystone versions prior to folsom-rc1 OpenStack Essex (2012.1) **Description** The issue allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. **Recommendations** For OpenStack Keystone versions prior to folsom-rc1, update to folsom-rc1 or later to resolve the issue. For OpenStack Essex (2012.1), consider upgrading to a newer version that is not affected by this issue. As a temporary workaround, consider restricting access to the administrative API to minimize the risk of exploitation.