CVE-2012-4413
published 2012-09-18CVE-2012-4413: OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the…
PriorityP420medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
1.88%
77.1th percentile
OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2012.1.1-6 (bookworm) | keystone 2012.1.1-6 (bookworm) |
| openstack | keystone | — | — |
| openstack | keystone | >= 0 < 2012.1.1-6 | 2012.1.1-6 |
| openstack | keystone | >= 0 < 2012.1.1-6 | 2012.1.1-6 |
| openstack | keystone | >= 0 < 2012.1.1-6 | 2012.1.1-6 |
| openstack | keystone | >= 0 < 2012.1.1-6 | 2012.1.1-6 |
| openstack | keystone | >= 0 < 2012.1.3 | 2012.1.3 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Keystone vulnerability
vendor_ubuntu·2012-09-13
CVE-2012-4413 OpenStack Keystone vulnerability
Title: OpenStack Keystone vulnerability
Summary: OpenStack Keystone did not properly handle user role changes
Dolph Mathews discovered that when roles are granted and revoked to
users in Keystone, pre-existing tokens were not updated or invalidated
to take the new roles into account. An attacker could use this to
continue to access resources that have been revoked.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
OpenStack-Keystone: role revocation token issues
vendor_redhat·2012-09-12·CVSS 4.0
CVE-2012-4413 [MEDIUM] CWE-613 OpenStack-Keystone: role revocation token issues
OpenStack-Keystone: role revocation token issues
OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.
Debian
CVE-2012-4413: keystone - OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or...
vendor_debian·2012·CVSS 4.0
CVE-2012-4413 [MEDIUM] CVE-2012-4413: keystone - OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or...
OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.
Scope: local
bookworm: resolved (fixed in 2012.1.1-6)
bullseye: resolved (fixed in 2012.1.1-6)
forky: resolved (fixed in 2012.1.1-6)
sid: resolved (fixed in 2012.1.1-6)
trixie: resolved (fixed in 2012.1.1-6)
GHSA
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles
ghsa·2022-05-17
CVE-2012-4413 [MEDIUM] OpenStack Keystone does not invalidate existing tokens when granting or revoking roles
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles
OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.
OSV
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles
osv·2022-05-17
CVE-2012-4413 [MEDIUM] OpenStack Keystone does not invalidate existing tokens when granting or revoking roles
OpenStack Keystone does not invalidate existing tokens when granting or revoking roles
OpenStack Keystone before 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.
OSV
CVE-2012-4413: OpenStack Keystone 2012
osv·2012-09-18·CVSS 4.0
CVE-2012-4413 [MEDIUM] CVE-2012-4413: OpenStack Keystone 2012
OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4413 OpenStack-Keystone: role revocation token issues [fedora-all]
bugzilla·2012-09-12·CVSS 4.0
CVE-2012-4413 [MEDIUM] CVE-2012-4413 OpenStack-Keystone: role revocation token issues [fedora-all]
CVE-2012-4413 OpenStack-Keystone: role revocation token issues [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security
Bugzilla
CVE-2012-4413 OpenStack-Keystone: role revocation token issues [epel-6]
bugzilla·2012-09-12·CVSS 4.0
CVE-2012-4413 [MEDIUM] CVE-2012-4413 OpenStack-Keystone: role revocation token issues [epel-6]
CVE-2012-4413 OpenStack-Keystone: role revocation token issues [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bug
Bugzilla
CVE-2012-4413 OpenStack-Keystone: role revocation token issues
bugzilla·2012-09-08·CVSS 4.0
CVE-2012-4413 [MEDIUM] CVE-2012-4413 OpenStack-Keystone: role revocation token issues
CVE-2012-4413 OpenStack-Keystone: role revocation token issues
Russell Bryant ([email protected]) of the OpenStack Project reports:
Title: Revoking a role does not affect existing tokens
Impact: High
Reporter: Dolph Mathews (Rackspace)
Products: Keystone
Affects: Essex, Folsom
Description:
Dolph Mathews reported a vulnerability in Keystone. Granting and
revoking roles from a user is not reflected upon token validation for
pre-existing tokens. Pre-existing tokens continue to be valid for the
original set of roles for the remainder of the token's lifespan, or
until explicitly invalidated. This fix invalidates all tokens held by
a user upon role grant/revoke to circumvent the issue.
Discussion:
See the attached patches. For Essex, the following patch also needs to
be in place before the
http://osvdb.org/85484http://secunia.com/advisories/50531http://secunia.com/advisories/50590http://www.openwall.com/lists/oss-security/2012/09/12/7http://www.securityfocus.com/bid/55524http://www.ubuntu.com/usn/USN-1564-1https://exchange.xforce.ibmcloud.com/vulnerabilities/78478http://osvdb.org/85484http://secunia.com/advisories/50531http://secunia.com/advisories/50590http://www.openwall.com/lists/oss-security/2012/09/12/7http://www.securityfocus.com/bid/55524http://www.ubuntu.com/usn/USN-1564-1https://exchange.xforce.ibmcloud.com/vulnerabilities/78478
2012-09-18
Published