CVE-2012-5571

Currently unrated

Key Information:

Vendor
Openstack
Vendor
CVE Published:
18 December 2012

Summary

OpenStack Keystone Essex (2012.1) and Folsom (2012.2) does not properly handle EC2 tokens when the user role has been removed from a tenant, which allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for the removed user role.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.