Описание
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 2012.2~f3-0ubuntu1 |
| hardy | DNE | |
| lucid | DNE | |
| natty | DNE | |
| oneiric | ignored | |
| precise | released | 2012.1+stable~20120824-a16a0ab9-0ubuntu2 |
| quantal | not-affected | 2012.2~f3-0ubuntu1 |
| upstream | released | 2012.1.1-9 |
Показывать по
EPSS
7.5 High
CVSS2
Связанные уязвимости
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Es ...
EPSS
7.5 High
CVSS2