CVE-2012-5571
OpenStack Keystone Essex/Folsom - Auth Bypass
Title source: llmDescription
OpenStack Keystone Essex (2012.1) and Folsom (2012.2) does not properly handle EC2 tokens when the user role has been removed from a tenant, which allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for the removed user role.
References (14)
Scores
EPSS
0.0017
EPSS Percentile
38.5%
Classification
CWE
CWE-255
Status
draft
Affected Products (4)
openstack/essex
openstack/folsom
pypi/Keystone
< 8.0.0a0PyPI
pypi/keystone
PyPI
Timeline
Published
Dec 18, 2012
Tracked Since
Feb 18, 2026