CVE-2012-3426
published 2012-07-31CVE-2012-3426: OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows…
PriorityP427medium4.9CVSS 2.0
AVNACMAuSCPIPAN
EPSS
2.28%
81.3th percentile
OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2012.1.1-1 (bookworm) | keystone 2012.1.1-1 (bookworm) |
| debian | keystone | — | — |
| openstack | folsom | — | — |
| openstack | horizon | — | — |
| openstack | keystone | < f9d4766249a72d8f88d75dcf1575b28dd3496681 | f9d4766249a72d8f88d75dcf1575b28dd3496681 |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | >= 0 < 2012.1.1-1 | 2012.1.1-1 |
| openstack | keystone | >= 0 < 2012.1.1-1 | 2012.1.1-1 |
| openstack | keystone | >= 0 < 2012.1.1-1 | 2012.1.1-1 |
| openstack | keystone | >= 0 < 2012.1.1-1 | 2012.1.1-1 |
| openstack | keystone | >= 0 < 8.0.0a0 | 8.0.0a0 |
| openstack | keystone | >= 0 < 8.0.0 | 8.0.0 |
| openstack | keystone | >= 0 < 38c7e46a640a94da4da89a39a5a1ea9c081f1eb5 | 38c7e46a640a94da4da89a39a5a1ea9c081f1eb5 |
| openstack | keystone | >= 14.0.0 < 27.0.2 | 27.0.2 |
| openstack | keystone | >= 14.0.0 < 27.0.2 | 27.0.2 |
| openstack | keystone | >= 14.0.0 < 27.0.2 | 27.0.2 |
| openstack | keystone | >= 28.0.0 < 28.0.2 | 28.0.2 |
| openstack | keystone | >= 28.0.0 < 28.0.2 | 28.0.2 |
| openstack | keystone | >= 28.0.0 < 28.0.2 | 28.0.2 |
| openstack | keystone | >= 29.0.0 < 29.0.2 | 29.0.2 |
| openstack | keystone | >= 29.0.0 < 29.0.2 | 29.0.2 |
| openstack | keystone | >= 29.0.0 < 29.0.2 | 29.0.2 |
CVSS provenance
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
ghsa4.9MEDIUM
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-whqr-fgm5-x77q: An issue was discovered in OpenStack Keystone before 29
ghsa_unreviewed·2026-05-28·CVSS 4.9
CVE-2026-44394 [MEDIUM] CWE-863 GHSA-whqr-fgm5-x77q: An issue was discovered in OpenStack Keystone before 29
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected.
GHSA
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
ghsa·2026-05-28·CVSS 4.9
CVE-2026-44394 [MEDIUM] CWE-863 OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity
GHSA
OpenStack Keystone token expiration issues
ghsa·2022-05-17
CVE-2012-3426 [MEDIUM] OpenStack Keystone token expiration issues
OpenStack Keystone token expiration issues
OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.
OSV
OpenStack Keystone Insufficient token expiration
osv·2022-05-17·CVSS 4.9
CVE-2012-5563 [MEDIUM] OpenStack Keystone Insufficient token expiration
OpenStack Keystone Insufficient token expiration
OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.
OSV
OpenStack Keystone token expiration issues
osv·2022-05-17
CVE-2012-3426 [MEDIUM] OpenStack Keystone token expiration issues
OpenStack Keystone token expiration issues
OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.
GHSA
OpenStack Keystone Insufficient token expiration
ghsa·2022-05-17·CVSS 4.9
CVE-2012-5563 [MEDIUM] CWE-324 OpenStack Keystone Insufficient token expiration
OpenStack Keystone Insufficient token expiration
OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.
OSV
CVE-2012-5563: OpenStack Keystone, as used in OpenStack Folsom 2012
osv·2012-12-18·CVSS 4.9
CVE-2012-5563 [MEDIUM] CVE-2012-5563: OpenStack Keystone, as used in OpenStack Folsom 2012
OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.
OSV
CVE-2012-3426: OpenStack Keystone before 2012
osv·2012-07-31·CVSS 4.9
CVE-2012-3426 [MEDIUM] CVE-2012-3426: OpenStack Keystone before 2012
OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.
Ubuntu
OpenStack Keystone vulnerabilities
vendor_ubuntu·2012-11-28·CVSS 4.9
CVE-2012-5563 [MEDIUM] OpenStack Keystone vulnerabilities
Title: OpenStack Keystone vulnerabilities
Summary: Keystone would allow unintended access to files over the network.
Vijaya Erukala discovered that Keystone did not properly invalidate
EC2-style credentials such that if credentials were removed from a tenant,
an authenticated and authorized user using those credentials may still be
allowed access beyond the account owner's expectations. (CVE-2012-5571)
It was discovered that Keystone did not properly implement token
expiration. A remote attacker could use this to continue to access an
account that is disabled or has a changed password. This issue was
previously fixed as CVE-2012-3426 but was reintroduced in Ubuntu 12.10.
(CVE-2012-5563)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
OpenStack: Keystone extension of token validity through token chaining
vendor_redhat·2012-11-28·CVSS 4.9
CVE-2012-5563 [MEDIUM] OpenStack: Keystone extension of token validity through token chaining
OpenStack: Keystone extension of token validity through token chaining
OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.
Ubuntu
OpenStack Keystone vulnerabilities
vendor_ubuntu·2012-09-03·CVSS 4.9
CVE-2012-3426 [MEDIUM] OpenStack Keystone vulnerabilities
Title: OpenStack Keystone vulnerabilities
Summary: Two security issues were fixed in OpenStack Keystone.
Dolph Mathews discovered that OpenStack Keystone did not properly
restrict to administrative users the ability to update users'
tenants. A remote attacker that can reach the administrative API can
use this to add any user to any tenant. (CVE-2012-3542)
Derek Higgins discovered that OpenStack Keystone did not properly
implement token expiration. A remote attacker could use this to
continue to access an account that has been disabled or has a changed
password. (CVE-2012-3426)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2012-5563: keystone - OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implem...
vendor_debian·2012·CVSS 4.9
CVE-2012-5563 [MEDIUM] CVE-2012-5563: keystone - OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implem...
OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2012-3426: keystone - OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 ...
vendor_debian·2012·CVSS 4.9
CVE-2012-3426 [MEDIUM] CVE-2012-3426: keystone - OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 ...
OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.
Scope: local
bookworm: resolved (fixed in 2012.1.1-1)
bullseye: resolved (fixed in 2012.1.1-1)
forky: resolved (fixed in 2012.1.1-1)
sid: resolved (fixed in 2012.1.1-1)
trixie: resolved (fixed in 2012.1.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44394 openstack-keystone: OpenStack Keystone: Federated token rescoping allows indefinite access
bugzilla·2026-05-28·CVSS 4.9
CVE-2026-44394 [MEDIUM] CVE-2026-44394 openstack-keystone: OpenStack Keystone: Federated token rescoping allows indefinite access
CVE-2026-44394 openstack-keystone: OpenStack Keystone: Federated token rescoping allows indefinite access
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect
Bugzilla
CVE-2012-5563 OpenStack: Keystone extension of token validity through token chaining
bugzilla·2012-11-22·CVSS 4.9
CVE-2012-5563 [MEDIUM] CVE-2012-5563 OpenStack: Keystone extension of token validity through token chaining
CVE-2012-5563 OpenStack: Keystone extension of token validity through token chaining
Thierry Carrez ([email protected]) of the OpenStack project reports:
Anndy reported a vulnerability in token chaining in Keystone. A token
expiration date can be circumvented by creating a new token before the
old one has expired. An authenticated and authorized user could
potentially leverage this vulnerability to extend his access beyond the
account owner expectations. Note: this vulnerability was fixed in the
past (CVE-2012-3426) but was reintroduced in Folsom when code was
refactored to support PKI tokens.
Discussion:
Created attachment 650039
CVE-2012-5563-keystone.patch includes test case
---
Acknowledgements:
Red Hat would like to thank the OpenStack project for reporting this issue. Upst
Bugzilla
CVE-2012-3426 OpenStack-Keystone: token expiration issues
bugzilla·2012-07-26·CVSS 4.9
CVE-2012-3426 [MEDIUM] CVE-2012-3426 OpenStack-Keystone: token expiration issues
CVE-2012-3426 OpenStack-Keystone: token expiration issues
Thierry Carrez ([email protected]) of the OpenStack project reports:
Derek Higgins reported various issues affecting Keystone token
expiration. A token expiration date can be circumvented by
continuously creating new tokens before the old one has expired.
Existing tokens also remain valid after a user account is disabled or
after an account password changed. An authenticated and authorized
user could potentially leverage those vulnerabilities to extend his
access beyond the account owner expectations.
Folsom fixes:
http://github.com/openstack/keystone/commit/375838cfceb88cacc312ff6564e64eb18ee6a355
http://github.com/openstack/keystone/commit/628149b3dc6b58b91fd08e6ca8d91c728ccb8626
http://github.com/openstack/keystone/commit/
http://github.com/openstack/keystone/commit/29e74e73a6e51cffc0371b32354558391826a4aahttp://github.com/openstack/keystone/commit/375838cfceb88cacc312ff6564e64eb18ee6a355http://github.com/openstack/keystone/commit/628149b3dc6b58b91fd08e6ca8d91c728ccb8626http://github.com/openstack/keystone/commit/a67b24878a6156eab17b9098fa649f0279256f5dhttp://github.com/openstack/keystone/commit/d9600434da14976463a0bd03abd8e0309f0db454http://github.com/openstack/keystone/commit/ea03d05ed5de0c015042876100d37a6a14bf56dehttp://secunia.com/advisories/50045http://secunia.com/advisories/50494http://www.openwall.com/lists/oss-security/2012/07/27/4http://www.ubuntu.com/usn/USN-1552-1https://bugs.launchpad.net/keystone/+bug/996595https://bugs.launchpad.net/keystone/+bug/997194https://bugs.launchpad.net/keystone/+bug/998185https://launchpad.net/keystone/essex/2012.1.1/+download/keystone-2012.1.1.tar.gzhttp://github.com/openstack/keystone/commit/29e74e73a6e51cffc0371b32354558391826a4aahttp://github.com/openstack/keystone/commit/375838cfceb88cacc312ff6564e64eb18ee6a355http://github.com/openstack/keystone/commit/628149b3dc6b58b91fd08e6ca8d91c728ccb8626http://github.com/openstack/keystone/commit/a67b24878a6156eab17b9098fa649f0279256f5dhttp://github.com/openstack/keystone/commit/d9600434da14976463a0bd03abd8e0309f0db454http://github.com/openstack/keystone/commit/ea03d05ed5de0c015042876100d37a6a14bf56dehttp://secunia.com/advisories/50045http://secunia.com/advisories/50494http://www.openwall.com/lists/oss-security/2012/07/27/4http://www.ubuntu.com/usn/USN-1552-1https://bugs.launchpad.net/keystone/+bug/996595https://bugs.launchpad.net/keystone/+bug/997194https://bugs.launchpad.net/keystone/+bug/998185https://launchpad.net/keystone/essex/2012.1.1/+download/keystone-2012.1.1.tar.gz
2012-07-31
Published