CVE-2012-3542
published 2012-09-05CVE-2012-3542: OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an…
PriorityP423medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.48%
82.9th percentile
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | horizon | < horizon 2012.1.1-4 (bookworm) | horizon 2012.1.1-4 (bookworm) |
| debian | keystone | < keystone 2012.1.1-5 (bookworm) | keystone 2012.1.1-5 (bookworm) |
| openstack | essex | — | — |
| openstack | horizon | — | — |
| openstack | horizon | — | — |
| openstack | horizon | >= 0 < 2012.1.1-4 | 2012.1.1-4 |
| openstack | horizon | >= 0 < 2012.1.1-4 | 2012.1.1-4 |
| openstack | horizon | >= 0 < 2012.1.1-4 | 2012.1.1-4 |
| openstack | horizon | >= 0 < 2012.1.1-4 | 2012.1.1-4 |
| openstack | keystone | >= 0 < 2012.1.1-5 | 2012.1.1-5 |
| openstack | keystone | >= 0 < 2012.1.1-5 | 2012.1.1-5 |
| openstack | keystone | >= 0 < 2012.1.1-5 | 2012.1.1-5 |
| openstack | keystone | >= 0 < 2012.1.1-5 | 2012.1.1-5 |
| openstack | keystone | >= 0 < 2012.1 | 2012.1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa5.8MEDIUM
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Keystone vulnerabilities
vendor_ubuntu·2012-09-03·CVSS 4.9
CVE-2012-3426 [MEDIUM] OpenStack Keystone vulnerabilities
Title: OpenStack Keystone vulnerabilities
Summary: Two security issues were fixed in OpenStack Keystone.
Dolph Mathews discovered that OpenStack Keystone did not properly
restrict to administrative users the ability to update users'
tenants. A remote attacker that can reach the administrative API can
use this to add any user to any tenant. (CVE-2012-3542)
Derek Higgins discovered that OpenStack Keystone did not properly
implement token expiration. A remote attacker could use this to
continue to access an account that has been disabled or has a changed
password. (CVE-2012-3426)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Keystone: Lack of authorization for adding users to tenants
vendor_redhat·2012-08-30·CVSS 5.8
CVE-2012-3542 [MEDIUM] Keystone: Lack of authorization for adding users to tenants
Keystone: Lack of authorization for adding users to tenants
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540.
Red Hat
OpenStack-Horizon: Open redirect through 'next' parameter
vendor_redhat·2012-08-30·CVSS 5.8
CVE-2012-3540 [MEDIUM] OpenStack-Horizon: Open redirect through 'next' parameter
OpenStack-Horizon: Open redirect through 'next' parameter
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake.
Debian
CVE-2012-3540: horizon - Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horiz...
vendor_debian·2012·CVSS 5.8
CVE-2012-3540 [MEDIUM] CVE-2012-3540: horizon - Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horiz...
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake.
Scope: local
bookworm: resolved (fixed in 2012.1.1-4)
bullseye: resolved (fixed in 2012.1.1-4)
forky: resolved (fixed in 2012.1.1-4)
sid: resolved (fixed in 2012.1.1-4)
trixie: resolved (fixed in 2012.1.1-4)
Debian
CVE-2012-3542: keystone - OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack ...
vendor_debian·2012·CVSS 5.8
CVE-2012-3542 [MEDIUM] CVE-2012-3542: keystone - OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack ...
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540.
Scope: local
bookworm: resolved (fixed in 2012.1.1-5)
bullseye: resolved (fixed in 2012.1.1-5)
forky: resolved (fixed in 2012.1.1-5)
sid: resolved (fixed in 2012.1.1-5)
trixie: resolved (fixed in 2012.1.1-5)
GHSA
OpenStack Keystone Allows Remote User Account Creation
ghsa·2022-05-17·CVSS 5.8
CVE-2012-3542 [MEDIUM] CWE-284 OpenStack Keystone Allows Remote User Account Creation
OpenStack Keystone Allows Remote User Account Creation
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540.
OSV
OpenStack Keystone Allows Remote User Account Creation
osv·2022-05-17·CVSS 5.8
CVE-2012-3542 [MEDIUM] OpenStack Keystone Allows Remote User Account Creation
OpenStack Keystone Allows Remote User Account Creation
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540.
GHSA
GHSA-j72v-mpwp-rg79: Open redirect vulnerability in views/auth_forms
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2012-3540 [MEDIUM] CWE-20 GHSA-j72v-mpwp-rg79: Open redirect vulnerability in views/auth_forms
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake.
OSV
CVE-2012-3542: OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012
osv·2012-09-05·CVSS 5.8
CVE-2012-3542 [MEDIUM] CVE-2012-3542: OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540.
OSV
CVE-2012-3540: Open redirect vulnerability in views/auth_forms
osv·2012-09-05·CVSS 5.8
CVE-2012-3540 [MEDIUM] CVE-2012-3540: Open redirect vulnerability in views/auth_forms
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3542 OpenStack Keystone: Lack of authorization for adding users to tenants [fedora-all]
bugzilla·2012-08-30·CVSS 4.3
CVE-2012-3542 [MEDIUM] CVE-2012-3542 OpenStack Keystone: Lack of authorization for adding users to tenants [fedora-all]
CVE-2012-3542 OpenStack Keystone: Lack of authorization for adding users to tenants [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/update
Bugzilla
CVE-2012-3542 OpenStack Keystone: Lack of authorization for adding users to tenants [epel-6]
bugzilla·2012-08-30·CVSS 4.3
CVE-2012-3542 [MEDIUM] CVE-2012-3542 OpenStack Keystone: Lack of authorization for adding users to tenants [epel-6]
CVE-2012-3542 OpenStack Keystone: Lack of authorization for adding users to tenants [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/ne
Bugzilla
CVE-2012-3542 OpenStack Keystone: Lack of authorization for adding users to tenants
bugzilla·2012-08-28·CVSS 4.3
CVE-2012-3542 [MEDIUM] CVE-2012-3542 OpenStack Keystone: Lack of authorization for adding users to tenants
CVE-2012-3542 OpenStack Keystone: Lack of authorization for adding users to tenants
Russel Bryant ([email protected]) on behalf of the OpenStack project reports:
Title: Lack of authorization for adding users to tenants
Impact: Critical
Reporter: Dolph Mathews (Rackspace)
Products: Keystone
Affects: Essex, Folsom
Description:
Dolph Mathews reported a vulnerability in Keystone. When attempting to
update a user's default tenant, Keystone will only partially deny the
request when a user is not authorized to complete this action. The API
responds with 401 Not Authorized and the user's default tenant is not
changed. However, the user is still granted membership to this new
tenant. The result is that any client that can reach the
administrative API (deployed on port 35357, by default) can add
http://secunia.com/advisories/50467http://secunia.com/advisories/50494http://www.openwall.com/lists/oss-security/2012/08/30/6http://www.securityfocus.com/bid/55326http://www.ubuntu.com/usn/USN-1552-1https://bugs.launchpad.net/keystone/+bug/1040626https://github.com/openstack/keystone/commit/5438d3b5a219d7c8fa67e66e538d325a61617155https://github.com/openstack/keystone/commit/c13d0ba606f7b2bdc609a7f388334e5efec3f3aahttps://lists.launchpad.net/openstack/msg16282.htmlhttp://secunia.com/advisories/50467http://secunia.com/advisories/50494http://www.openwall.com/lists/oss-security/2012/08/30/6http://www.securityfocus.com/bid/55326http://www.ubuntu.com/usn/USN-1552-1https://bugs.launchpad.net/keystone/+bug/1040626https://github.com/openstack/keystone/commit/5438d3b5a219d7c8fa67e66e538d325a61617155https://github.com/openstack/keystone/commit/c13d0ba606f7b2bdc609a7f388334e5efec3f3aahttps://lists.launchpad.net/openstack/msg16282.html
2012-09-05
Published