Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-5571

Опубликовано: 18 дек. 2012
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.5

Описание

OpenStack Keystone Essex (2012.1) and Folsom (2012.2) does not properly handle EC2 tokens when the user role has been removed from a tenant, which allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for the removed user role.

РелизСтатусПримечание
devel

not-affected

2013.1~g1-0ubuntu1
hardy

DNE

lucid

DNE

oneiric

ignored

precise

released

2012.1+stable~20120824-a16a0ab9-0ubuntu2.3
quantal

released

2012.2-0ubuntu1.2
upstream

pending

2013.1

Показывать по

EPSS

Процентиль: 39%
0.00173
Низкий

3.5 Low

CVSS2

Связанные уязвимости

redhat
около 13 лет назад

OpenStack Keystone Essex (2012.1) and Folsom (2012.2) does not properly handle EC2 tokens when the user role has been removed from a tenant, which allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for the removed user role.

nvd
около 13 лет назад

OpenStack Keystone Essex (2012.1) and Folsom (2012.2) does not properly handle EC2 tokens when the user role has been removed from a tenant, which allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for the removed user role.

debian
около 13 лет назад

OpenStack Keystone Essex (2012.1) and Folsom (2012.2) does not properl ...

github
больше 3 лет назад

OpenStack Keystone intended authorization restrictions bypass

EPSS

Процентиль: 39%
0.00173
Низкий

3.5 Low

CVSS2