PT-2012-6031 · Openstack · Openstack Keystone

Vijaya Erukala

·

Published

2012-12-18

·

Updated

2022-05-17

·

CVE-2012-5571

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Keystone versions 2012.1 through 2012.2
Description The issue allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for a removed user role, due to improper handling of EC2 tokens when the user role has been removed from a tenant.
Recommendations For versions 2012.1 and 2012.2, consider restricting access to EC2 tokens for removed user roles until a proper fix is applied. As a temporary workaround, review and manually revoke tokens for user roles that have been removed from a tenant to minimize the risk of exploitation.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-5571
GHSA-QVPR-QM6W-6RCC
PYSEC-2012-35
RHSA-2012:1556
RHSA-2012:1557

Affected Products

Openstack Keystone