Openstack · Openstack Keystone · CVE-2012-5571
**Name of the Vulnerable Software and Affected Versions**
OpenStack Keystone versions 2012.1 through 2012.2
**Description**
The issue allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for a removed user role, due to improper handling of EC2 tokens when the user role has been removed from a tenant.
**Recommendations**
For versions 2012.1 and 2012.2, consider restricting access to EC2 tokens for removed user roles until a proper fix is applied. As a temporary workaround, review and manually revoke tokens for user roles that have been removed from a tenant to minimize the risk of exploitation.