Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2012-3426

около 14 лет назад

OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2012-3426

около 14 лет назад

OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.

CVSS2: 4.9
EPSS: Низкий
debian логотип

CVE-2012-3426

около 14 лет назад

OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before ...

CVSS2: 4.9
EPSS: Низкий
github логотип

GHSA-xp97-6w7r-4cjc

около 4 лет назад

OpenStack Keystone token expiration issues

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-3426

OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.

CVSS2: 4.9
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3426

OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.

CVSS2: 4.9
2%
Низкий
около 14 лет назад
debian логотип
CVE-2012-3426

OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before ...

CVSS2: 4.9
2%
Низкий
около 14 лет назад
github логотип
GHSA-xp97-6w7r-4cjc

OpenStack Keystone token expiration issues

2%
Низкий
около 4 лет назад

Уязвимостей на страницу