PyPi: Keystone

CVE-2012-4456

Safety vulnerability ID: 35374

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Oct 09, 2012 Updated at Oct 02, 2024
Scan your Python projects for vulnerabilities →

Advisory

The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.

Affected package

keystone

Latest version: 26.0.0

OpenStack Identity

Affected versions

Fixed versions

Vulnerability changelog

The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.


MLIST:[openstack] 20120928 [OSSA 2012-015] Some actions in Keystone admin API do not validate token (CVE-2012-4456): https://lists.launchpad.net/openstack/msg17034.html
MLIST:[oss-security] 20120928 [OSSA 2012-015] Some actions in Keystone admin API do not validate token (CVE-2012-4456): http://www.openwall.com/lists/oss-security/2012/09/28/5
MISC:https://bugzilla.redhat.com/show_bug.cgi?id=861179: https://bugzilla.redhat.com/show_bug.cgi?id=861179
CONFIRM:https://bugs.launchpad.net/keystone/+bug/1006815: https://bugs.launchpad.net/keystone/+bug/1006815
CONFIRM:https://bugs.launchpad.net/keystone/+bug/1006822: https://bugs.launchpad.net/keystone/+bug/1006822
CONFIRM:https://github.com/openstack/keystone/commit/14b136aed9d988f5a8f3e699bd4577c9b874d6c1: https://github.com/openstack/keystone/commit/14b136aed9d988f5a8f3e699bd4577c9b874d6c1
CONFIRM:https://github.com/openstack/keystone/commit/1d146f5c32e58a73a677d308370f147a3271c2cb: https://github.com/openstack/keystone/commit/1d146f5c32e58a73a677d308370f147a3271c2cb
CONFIRM:https://github.com/openstack/keystone/commit/24df3adb3f50cbb5ada411bc67aba8a781e6a431: https://github.com/openstack/keystone/commit/24df3adb3f50cbb5ada411bc67aba8a781e6a431
CONFIRM:https://github.com/openstack/keystone/commit/868054992faa45d6f42d822bf1588cb88d7c9ccb: https://github.com/openstack/keystone/commit/868054992faa45d6f42d822bf1588cb88d7c9ccb
BID:55716: http://www.securityfocus.com/bid/55716
SECUNIA:50665: http://secunia.com/advisories/50665
XF:keystone-xauth-sec-bypass(78944): https://exchange.xforce.ibmcloud.com/vulnerabilities/78944

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

HIGH 7.5

CVSS v2 Details

HIGH 7.5
Access Vector (AV)
NETWORK
Access Complexity (AC)
LOW
Authentication (Au)
NONE
Confidentiality Impact (C)
PARTIAL
Integrity Impact (I)
PARTIAL
Availability Impact (A)
PARTIAL