PT-2012-6031 · Openstack · Openstack Keystone
Vijaya Erukala
·
Published
2012-12-18
·
Updated
2022-05-17
·
CVE-2012-5571
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Keystone versions 2012.1 through 2012.2
Description
The issue allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for a removed user role, due to improper handling of EC2 tokens when the user role has been removed from a tenant.
Recommendations
For versions 2012.1 and 2012.2, consider restricting access to EC2 tokens for removed user roles until a proper fix is applied. As a temporary workaround, review and manually revoke tokens for user roles that have been removed from a tenant to minimize the risk of exploitation.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openstack Keystone