VendorsOpenStackkeystone2012.2
Vulnerabilities

OpenStack Keystone 2012.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2012-4456
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.
Published 2012-10-09 · Modified
7.5EPSS 0.040
CVE-2013-4294
The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass intended access restrictions via a revoked PKI token.
Published 2013-09-23 · Modified
5.0EPSS 0.027
CVE-2012-4457
OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.
Published 2012-10-09 · Modified
4.0EPSS 0.023