CVE-2012-5571

OpenStack Keystone Essex/Folsom - Auth Bypass

Title source: llm

Description

OpenStack Keystone Essex (2012.1) and Folsom (2012.2) does not properly handle EC2 tokens when the user role has been removed from a tenant, which allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for the removed user role.

Scores

EPSS 0.0017
EPSS Percentile 38.5%

Classification

CWE
CWE-255
Status draft

Affected Products (4)

openstack/essex
openstack/folsom
pypi/Keystone < 8.0.0a0PyPI
pypi/keystone PyPI

Timeline

Published Dec 18, 2012
Tracked Since Feb 18, 2026