CVE-2012-4457
published 2012-10-09CVE-2012-4457: OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote…
PriorityP421medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
2.27%
81.1th percentile
OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2012.1.1-9 (bookworm) | keystone 2012.1.1-9 (bookworm) |
| openstack | keystone | — | — |
| openstack | keystone | >= 0 < 2012.1.1-9 | 2012.1.1-9 |
| openstack | keystone | >= 0 < 2012.1.1-9 | 2012.1.1-9 |
| openstack | keystone | >= 0 < 2012.1.1-9 | 2012.1.1-9 |
| openstack | keystone | >= 0 < 2012.1.1-9 | 2012.1.1-9 |
| openstack | keystone | >= 0 < 8.0.0a0 | 8.0.0a0 |
| openstack | keystone | >= 2012.1 < 2012.1.2 | 2012.1.2 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
2012.1.1: fails to raise Unauthorized user error for disabled tenant
vendor_redhat·2012-05-26·CVSS 4.0
CVE-2012-4457 [MEDIUM] 2012.1.1: fails to raise Unauthorized user error for disabled tenant
2012.1.1: fails to raise Unauthorized user error for disabled tenant
OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.
Debian
CVE-2012-4457: keystone - OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not pro...
vendor_debian·2012·CVSS 4.0
CVE-2012-4457 [MEDIUM] CVE-2012-4457: keystone - OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not pro...
OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.
Scope: local
bookworm: resolved (fixed in 2012.1.1-9)
bullseye: resolved (fixed in 2012.1.1-9)
forky: resolved (fixed in 2012.1.1-9)
sid: resolved (fixed in 2012.1.1-9)
trixie: resolved (fixed in 2012.1.1-9)
OSV
OpenStack Keystone Token authorization for a user in a disabled tenant is allowed
osv·2022-05-14
CVE-2012-4457 [MEDIUM] OpenStack Keystone Token authorization for a user in a disabled tenant is allowed
OpenStack Keystone Token authorization for a user in a disabled tenant is allowed
OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.
GHSA
OpenStack Keystone Token authorization for a user in a disabled tenant is allowed
ghsa·2022-05-14
CVE-2012-4457 [MEDIUM] CWE-287 OpenStack Keystone Token authorization for a user in a disabled tenant is allowed
OpenStack Keystone Token authorization for a user in a disabled tenant is allowed
OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.
OSV
CVE-2012-4457: OpenStack Keystone Essex before 2012
osv·2012-10-09·CVSS 4.0
CVE-2012-4457 [MEDIUM] CVE-2012-4457: OpenStack Keystone Essex before 2012
OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4457 OpenStack Keystone 2012.1.1: fails to raise Unauthorized user error for disabled tenant
bugzilla·2012-09-27·CVSS 4.0
CVE-2012-4457 [MEDIUM] CVE-2012-4457 OpenStack Keystone 2012.1.1: fails to raise Unauthorized user error for disabled tenant
CVE-2012-4457 OpenStack Keystone 2012.1.1: fails to raise Unauthorized user error for disabled tenant
Rohit Karajgi discovered a vulnerability in OpenStack Keystone token handling:
Token authentication for a user belonging to a disable tenant should not be
allowed.
External References:
https://bugs.launchpad.net/keystone/+bug/988920
Discussion:
Created openstack-keystone tracking bugs for this issue
Affects: fedora-all [bug 861182]
---
Created openstack-keystone tracking bugs for this issue
Affects: epel-6 [bug 861183]
---
Created attachment 618258
CVE-2012-4457-keystone-988920.patch
---
Official vendor advisory:
https://lists.launchpad.net/openstack/msg17036.html
---
Above is a reply, original OSSA 2012-016 post is
https://lists.launchpad.net/openstack/msg17035.html
---
T
Bugzilla
CVE-2012-4456 CVE-2012-4457 openstack-keystone various flaws [fedora-all]
bugzilla·2012-09-27·CVSS 7.5
CVE-2012-4456 [HIGH] CVE-2012-4456 CVE-2012-4457 openstack-keystone various flaws [fedora-all]
CVE-2012-4456 CVE-2012-4457 openstack-keystone various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&b
Bugzilla
CVE-2012-4456 CVE-2012-4457 openstack-keystone various flaws [epel-6]
bugzilla·2012-09-27·CVSS 7.5
CVE-2012-4456 [HIGH] CVE-2012-4456 CVE-2012-4457 openstack-keystone various flaws [epel-6]
CVE-2012-4456 CVE-2012-4457 openstack-keystone various flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=
http://secunia.com/advisories/50665http://www.openwall.com/lists/oss-security/2012/09/28/6http://www.securityfocus.com/bid/55716https://bugzilla.redhat.com/show_bug.cgi?id=861180https://exchange.xforce.ibmcloud.com/vulnerabilities/78947https://github.com/openstack/keystone/commit/4ebfdfaf23c6da8e3c182bf3ec2cb2b7132ef685https://github.com/openstack/keystone/commit/5373601bbdda10f879c08af1698852142b75f8d5https://lists.launchpad.net/openstack/msg17035.htmlhttp://secunia.com/advisories/50665http://www.openwall.com/lists/oss-security/2012/09/28/6http://www.securityfocus.com/bid/55716https://bugzilla.redhat.com/show_bug.cgi?id=861180https://exchange.xforce.ibmcloud.com/vulnerabilities/78947https://github.com/openstack/keystone/commit/4ebfdfaf23c6da8e3c182bf3ec2cb2b7132ef685https://github.com/openstack/keystone/commit/5373601bbdda10f879c08af1698852142b75f8d5https://lists.launchpad.net/openstack/msg17035.html
2012-10-09
Published