Description
OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5747 | OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant. |
Github GHSA |
GHSA-x8h4-xf47-pqc3 | OpenStack Keystone Token authorization for a user in a disabled tenant is allowed |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T20:35:09.684Z
Reserved: 2012-08-21T00:00:00.000Z
Link: CVE-2012-4457
No data.
Status : Modified
Published: 2012-10-09T15:55:01.237
Modified: 2026-04-29T01:13:23.040
Link: CVE-2012-4457
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA