cbcvebase.
CVE-2012-4413
published 2012-09-18

CVE-2012-4413: OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the…

PriorityP420medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
1.88%
77.1th percentile
OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.

Affected

7 ranges
VendorProductVersion rangeFixed in
debiankeystone< keystone 2012.1.1-6 (bookworm)keystone 2012.1.1-6 (bookworm)
openstackkeystone
openstackkeystone>= 0 < 2012.1.1-62012.1.1-6
openstackkeystone>= 0 < 2012.1.1-62012.1.1-6
openstackkeystone>= 0 < 2012.1.1-62012.1.1-6
openstackkeystone>= 0 < 2012.1.1-62012.1.1-6
openstackkeystone>= 0 < 2012.1.32012.1.3

CVSS provenance

nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.