VulnerabilityModified
CVE-2012-5571
This vulnerability allows remote authenticated users to bypass intended authorization restrictions.
MEDIUM 5.4EPSS 2.05%
Does this matter?
Lower severity and a low EPSS score (2.05%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly handle EC2 (Elastic Compute Cloud) tokens when a user's role has been removed from a tenant. An attacker can leverage a token associated with a removed user role to gain unauthorized access.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 2.05% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-639, CWE-255
- Affected
- openstack/essex · openstack/folsom
- Source
- secalert@redhat.com
References
- http://lists.fedoraproject.org/pipermail/package-announce/2012-December/094286.html
- http://rhn.redhat.com/errata/RHSA-2012-1556.html
- http://rhn.redhat.com/errata/RHSA-2012-1557.html
- http://secunia.com/advisories/51423Vendor Advisory
- http://secunia.com/advisories/51436Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/11/28/5Patch
- http://www.openwall.com/lists/oss-security/2012/11/28/6Patch
- http://www.securityfocus.com/bid/56726
- http://www.ubuntu.com/usn/USN-1641-1
- https://access.redhat.com/security/cve/CVE-2012-5571
- https://bugs.launchpad.net/keystone/+bug/1064914Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80333
- https://github.com/openstack/keystone/commit/37308dd4f3e33f7bd0f71d83fd51734d1870713bPatch
- https://github.com/openstack/keystone/commit/8735009dc5b895db265a1cd573f39f4acfca2a19Patch
- https://github.com/openstack/keystone/commit/9d68b40cb9ea818c48152e6c712ff41586ad9653Patch
- http://lists.fedoraproject.org/pipermail/package-announce/2012-December/094286.html
- http://rhn.redhat.com/errata/RHSA-2012-1556.html
- http://rhn.redhat.com/errata/RHSA-2012-1557.html
- http://secunia.com/advisories/51423Vendor Advisory
- http://secunia.com/advisories/51436Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/11/28/5Patch
- http://www.openwall.com/lists/oss-security/2012/11/28/6Patch
- http://www.securityfocus.com/bid/56726
- http://www.ubuntu.com/usn/USN-1641-1
- https://bugs.launchpad.net/keystone/+bug/1064914Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80333
- https://github.com/openstack/keystone/commit/37308dd4f3e33f7bd0f71d83fd51734d1870713bPatch
- https://github.com/openstack/keystone/commit/8735009dc5b895db265a1cd573f39f4acfca2a19Patch
- https://github.com/openstack/keystone/commit/9d68b40cb9ea818c48152e6c712ff41586ad9653Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.