CVE-2012-4456
OpenStack Keystone < 2012.1.2 - Improper Authentication via X-Auth-Token Validation
Title source: llmDescription
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.
References (12)
Core 12
Core References
Mailing List, Patch, Third Party Advisory mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/09/28/5
Third Party Advisory, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/50665
Patch, Third Party Advisory mailing-list
x_refsource_mlist
https://lists.launchpad.net/openstack/msg17034.html
Third Party Advisory x_refsource_confirm
https://github.com/openstack/keystone/commit/24df3adb3f50cbb5ada411bc67aba8a781e6a431
Third Party Advisory x_refsource_confirm
https://github.com/openstack/keystone/commit/14b136aed9d988f5a8f3e699bd4577c9b874d6c1
Patch, Third Party Advisory x_refsource_confirm
https://bugs.launchpad.net/keystone/+bug/1006822
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/55716
Third Party Advisory x_refsource_confirm
https://bugs.launchpad.net/keystone/+bug/1006815
Third Party Advisory x_refsource_confirm
https://github.com/openstack/keystone/commit/868054992faa45d6f42d822bf1588cb88d7c9ccb
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/78944
Third Party Advisory x_refsource_confirm
https://github.com/openstack/keystone/commit/1d146f5c32e58a73a677d308370f147a3271c2cb
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=861179
Scores
EPSS
0.0395
EPSS Percentile
88.5%
Details
CWE
CWE-287
Status
published
Products (3)
openstack/keystone
2012.2 milestone1
openstack/keystone
2012.1 - 2012.1.2
pypi/keystone
2012.1 - 2012.1.2PyPI
Published
Oct 09, 2012
Tracked Since
Feb 18, 2026