CVE-2012-4456
09.10.2012, 15:55
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.Enginsight
Vendor | Product | Version |
---|---|---|
openstack | keystone | 2012.1 ≤ 𝑥 < 2012.1.2 |
openstack | keystone | 2012.2:milestone1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References