CVE-2012-4456
published 2012-10-09CVE-2012-4456: The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token…
PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.96%
89.3th percentile
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2012.1.1-9 (bookworm) | keystone 2012.1.1-9 (bookworm) |
| openstack | keystone | — | — |
| openstack | keystone | >= 0 < 2012.1.1-9 | 2012.1.1-9 |
| openstack | keystone | >= 0 < 2012.1.1-9 | 2012.1.1-9 |
| openstack | keystone | >= 0 < 2012.1.1-9 | 2012.1.1-9 |
| openstack | keystone | >= 0 < 2012.1.1-9 | 2012.1.1-9 |
| openstack | keystone | >= 2012.1 < 2012.1.2 | 2012.1.2 |
| openstack | keystone | >= 2012.1 < 2012.1.2 | 2012.1.2 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Keystone Improper Authentication vulnerability
ghsa·2022-05-14
CVE-2012-4456 [HIGH] CWE-287 OpenStack Keystone Improper Authentication vulnerability
OpenStack Keystone Improper Authentication vulnerability
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.
OSV
OpenStack Keystone Improper Authentication vulnerability
osv·2022-05-14
CVE-2012-4456 [HIGH] OpenStack Keystone Improper Authentication vulnerability
OpenStack Keystone Improper Authentication vulnerability
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.
OSV
CVE-2012-4456: The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012
osv·2012-10-09·CVSS 7.5
CVE-2012-4456 [HIGH] CVE-2012-4456: The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.
Red Hat
2012.1.1: fails to validate tokens in Admin API
vendor_redhat·2012-05-31·CVSS 7.5
CVE-2012-4456 [HIGH] CWE-304 2012.1.1: fails to validate tokens in Admin API
2012.1.1: fails to validate tokens in Admin API
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.
Debian
CVE-2012-4456: keystone - The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before...
vendor_debian·2012·CVSS 7.5
CVE-2012-4456 [HIGH] CVE-2012-4456: keystone - The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before...
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.
Scope: local
bookworm: resolved (fixed in 2012.1.1-9)
bullseye: resolved (fixed in 2012.1.1-9)
forky: resolved (fixed in 2012.1.1-9)
sid: resolved (fixed in 2012.1.1-9)
trixie: resolved (fixed in 2012.1.1-9)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4456 CVE-2012-4457 openstack-keystone various flaws [fedora-all]
bugzilla·2012-09-27·CVSS 7.5
CVE-2012-4456 [HIGH] CVE-2012-4456 CVE-2012-4457 openstack-keystone various flaws [fedora-all]
CVE-2012-4456 CVE-2012-4457 openstack-keystone various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&b
Bugzilla
CVE-2012-4456 Openstack Keystone 2012.1.1: fails to validate tokens in Admin API
bugzilla·2012-09-27·CVSS 7.5
CVE-2012-4456 [HIGH] CVE-2012-4456 Openstack Keystone 2012.1.1: fails to validate tokens in Admin API
CVE-2012-4456 Openstack Keystone 2012.1.1: fails to validate tokens in Admin API
Jason Xu ([email protected]) discovered several vulnerabilities in OpenStack
Keystone token verification:
The first occurs in the API /v2.0/OS-KSADM/services and
/v2.0/OS-KSADM/services/{service_id}, the second occurs in
/v2.0/tenants/{tenant_id}/users/{user_id}/roles
In both cases the OpenStack Keystone code fails to check if the tokens are
valid. These issues have been addressed by adding checks in the form of
test_service_crud_requires_auth() and test_user_role_list_requires_auth().
External references:
https://bugs.launchpad.net/keystone/+bug/1006822
https://bugs.launchpad.net/keystone/+bug/1006815
Discussion:
Created openstack-keystone tracking bugs for this issue
Affects: fedora-all [bug 861182]
Bugzilla
CVE-2012-4456 CVE-2012-4457 openstack-keystone various flaws [epel-6]
bugzilla·2012-09-27·CVSS 7.5
CVE-2012-4456 [HIGH] CVE-2012-4456 CVE-2012-4457 openstack-keystone various flaws [epel-6]
CVE-2012-4456 CVE-2012-4457 openstack-keystone various flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=
http://secunia.com/advisories/50665http://www.openwall.com/lists/oss-security/2012/09/28/5http://www.securityfocus.com/bid/55716https://bugs.launchpad.net/keystone/+bug/1006815https://bugs.launchpad.net/keystone/+bug/1006822https://bugzilla.redhat.com/show_bug.cgi?id=861179https://exchange.xforce.ibmcloud.com/vulnerabilities/78944https://github.com/openstack/keystone/commit/14b136aed9d988f5a8f3e699bd4577c9b874d6c1https://github.com/openstack/keystone/commit/1d146f5c32e58a73a677d308370f147a3271c2cbhttps://github.com/openstack/keystone/commit/24df3adb3f50cbb5ada411bc67aba8a781e6a431https://github.com/openstack/keystone/commit/868054992faa45d6f42d822bf1588cb88d7c9ccbhttps://lists.launchpad.net/openstack/msg17034.htmlhttp://secunia.com/advisories/50665http://www.openwall.com/lists/oss-security/2012/09/28/5http://www.securityfocus.com/bid/55716https://bugs.launchpad.net/keystone/+bug/1006815https://bugs.launchpad.net/keystone/+bug/1006822https://bugzilla.redhat.com/show_bug.cgi?id=861179https://exchange.xforce.ibmcloud.com/vulnerabilities/78944https://github.com/openstack/keystone/commit/14b136aed9d988f5a8f3e699bd4577c9b874d6c1https://github.com/openstack/keystone/commit/1d146f5c32e58a73a677d308370f147a3271c2cbhttps://github.com/openstack/keystone/commit/24df3adb3f50cbb5ada411bc67aba8a781e6a431https://github.com/openstack/keystone/commit/868054992faa45d6f42d822bf1588cb88d7c9ccbhttps://lists.launchpad.net/openstack/msg17034.html
2012-10-09
Published