Логотип exploitDog
bind:CVE-2012-3426
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2012-3426

Количество 4

Количество 4

ubuntu логотип

CVE-2012-3426

больше 13 лет назад

OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2012-3426

больше 13 лет назад

OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.

CVSS2: 4.9
EPSS: Низкий
debian логотип

CVE-2012-3426

больше 13 лет назад

OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before ...

CVSS2: 4.9
EPSS: Низкий
github логотип

GHSA-xp97-6w7r-4cjc

больше 3 лет назад

OpenStack Keystone token expiration issues

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-3426

OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.

CVSS2: 4.9
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-3426

OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.

CVSS2: 4.9
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-3426

OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before ...

CVSS2: 4.9
0%
Низкий
больше 13 лет назад
github логотип
GHSA-xp97-6w7r-4cjc

OpenStack Keystone token expiration issues

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу