Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-5571

Опубликовано: 18 дек. 2012
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.5
CVSS3: 5.4

Описание

A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly handle EC2 (Elastic Compute Cloud) tokens when a user's role has been removed from a tenant. An attacker can leverage a token associated with a removed user role to gain unauthorized access.

РелизСтатусПримечание
devel

not-affected

2013.1~g1-0ubuntu1
hardy

DNE

lucid

DNE

oneiric

ignored

precise

released

2012.1+stable~20120824-a16a0ab9-0ubuntu2.3
quantal

released

2012.2-0ubuntu1.2
upstream

pending

2013.1

Показывать по

EPSS

Процентиль: 79%
0.02055
Низкий

3.5 Low

CVSS2

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
redhat
больше 13 лет назад

A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly handle EC2 (Elastic Compute Cloud) tokens when a user's role has been removed from a tenant. An attacker can leverage a token associated with a removed user role to gain unauthorized access.

CVSS3: 5.4
nvd
больше 13 лет назад

A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly handle EC2 (Elastic Compute Cloud) tokens when a user's role has been removed from a tenant. An attacker can leverage a token associated with a removed user role to gain unauthorized access.

CVSS3: 5.4
debian
больше 13 лет назад

A flaw was found in OpenStack Keystone. This vulnerability allows remo ...

CVSS3: 5.4
github
около 4 лет назад

OpenStack Keystone intended authorization restrictions bypass

EPSS

Процентиль: 79%
0.02055
Низкий

3.5 Low

CVSS2

5.4 Medium

CVSS3