Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-4457

Опубликовано: 26 мая 2012
Источник: redhat
CVSS2: 4
EPSS Низкий

Описание

OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=8611802012.1.1: fails to raise Unauthorized user error for disabled tenant

EPSS

Процентиль: 81%
0.02267
Низкий

4 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 14 лет назад

OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.

nvd
почти 14 лет назад

OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.

debian
почти 14 лет назад

OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 do ...

github
около 4 лет назад

OpenStack Keystone Token authorization for a user in a disabled tenant is allowed

EPSS

Процентиль: 81%
0.02267
Низкий

4 Medium

CVSS2