CVE Vulnerabilities

CVE-2012-4413

Published: Sep 18, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
4 MODERATE
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.

Affected Software

NameVendorStart VersionEnd Version
KeystoneOpenstack2012.1.3 (including)2012.1.3 (including)
OpenStack Essex for RHEL 6RedHatopenstack-keystone-0:2012.1.2-4.el6*
KeystoneUbuntuoneiric*
KeystoneUbuntuprecise*
KeystoneUbuntuupstream*

References