VulnerabilityModified
CVE-2012-4413
OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.
MEDIUM 4.0EPSS 1.90%
Does this matter?
Lower severity and a low EPSS score (1.90%). Track it; it rarely justifies an emergency change on its own.
Description
OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
- EPSS
- 1.90% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- openstack/keystone
- Source
- secalert@redhat.com
References
- http://osvdb.org/85484
- http://secunia.com/advisories/50531Vendor Advisory
- http://secunia.com/advisories/50590Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/09/12/7
- http://www.securityfocus.com/bid/55524
- http://www.ubuntu.com/usn/USN-1564-1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78478
- http://osvdb.org/85484
- http://secunia.com/advisories/50531Vendor Advisory
- http://secunia.com/advisories/50590Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/09/12/7
- http://www.securityfocus.com/bid/55524
- http://www.ubuntu.com/usn/USN-1564-1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78478
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.