CVE-2012-5563
published 2012-12-18CVE-2012-5563: OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass…
PriorityP420medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
2.86%
85.8th percentile
OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | — | — |
| openstack | folsom | — | — |
| openstack | keystone | < f9d4766249a72d8f88d75dcf1575b28dd3496681 | f9d4766249a72d8f88d75dcf1575b28dd3496681 |
| openstack | keystone | >= 0 < 8.0.0 | 8.0.0 |
| openstack | keystone | >= 0 < 38c7e46a640a94da4da89a39a5a1ea9c081f1eb5 | 38c7e46a640a94da4da89a39a5a1ea9c081f1eb5 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
ghsa4.9MEDIUM
osv4.9MEDIUM
vendor_debian4.9LOW
vendor_redhat4.9MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Keystone vulnerabilities
vendor_ubuntu·2012-11-28·CVSS 4.9
CVE-2012-5563 [MEDIUM] OpenStack Keystone vulnerabilities
Title: OpenStack Keystone vulnerabilities
Summary: Keystone would allow unintended access to files over the network.
Vijaya Erukala discovered that Keystone did not properly invalidate
EC2-style credentials such that if credentials were removed from a tenant,
an authenticated and authorized user using those credentials may still be
allowed access beyond the account owner's expectations. (CVE-2012-5571)
It was discovered that Keystone did not properly implement token
expiration. A remote attacker could use this to continue to access an
account that is disabled or has a changed password. This issue was
previously fixed as CVE-2012-3426 but was reintroduced in Ubuntu 12.10.
(CVE-2012-5563)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
OpenStack: Keystone extension of token validity through token chaining
vendor_redhat·2012-11-28·CVSS 4.9
CVE-2012-5563 [MEDIUM] OpenStack: Keystone extension of token validity through token chaining
OpenStack: Keystone extension of token validity through token chaining
OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.
Debian
CVE-2012-5563: keystone - OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implem...
vendor_debian·2012·CVSS 4.9
CVE-2012-5563 [MEDIUM] CVE-2012-5563: keystone - OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implem...
OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
OpenStack Keystone Insufficient token expiration
osv·2022-05-17·CVSS 4.9
CVE-2012-5563 [MEDIUM] OpenStack Keystone Insufficient token expiration
OpenStack Keystone Insufficient token expiration
OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.
GHSA
OpenStack Keystone Insufficient token expiration
ghsa·2022-05-17·CVSS 4.9
CVE-2012-5563 [MEDIUM] CWE-324 OpenStack Keystone Insufficient token expiration
OpenStack Keystone Insufficient token expiration
OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.
OSV
CVE-2012-5563: OpenStack Keystone, as used in OpenStack Folsom 2012
osv·2012-12-18·CVSS 4.9
CVE-2012-5563 [MEDIUM] CVE-2012-5563: OpenStack Keystone, as used in OpenStack Folsom 2012
OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2012-1557.htmlhttp://secunia.com/advisories/51423http://secunia.com/advisories/51436http://www.openwall.com/lists/oss-security/2012/11/28/5http://www.openwall.com/lists/oss-security/2012/11/28/6http://www.securityfocus.com/bid/56727http://www.ubuntu.com/usn/USN-1641-1https://bugs.launchpad.net/keystone/+bug/1079216https://exchange.xforce.ibmcloud.com/vulnerabilities/80370https://github.com/openstack/keystone/commit/38c7e46a640a94da4da89a39a5a1ea9c081f1eb5https://github.com/openstack/keystone/commit/f9d4766249a72d8f88d75dcf1575b28dd3496681http://rhn.redhat.com/errata/RHSA-2012-1557.htmlhttp://secunia.com/advisories/51423http://secunia.com/advisories/51436http://www.openwall.com/lists/oss-security/2012/11/28/5http://www.openwall.com/lists/oss-security/2012/11/28/6http://www.securityfocus.com/bid/56727http://www.ubuntu.com/usn/USN-1641-1https://bugs.launchpad.net/keystone/+bug/1079216https://exchange.xforce.ibmcloud.com/vulnerabilities/80370https://github.com/openstack/keystone/commit/38c7e46a640a94da4da89a39a5a1ea9c081f1eb5https://github.com/openstack/keystone/commit/f9d4766249a72d8f88d75dcf1575b28dd3496681
2012-12-18
Published