CVE-2012-5571
Publication date 28 November 2012
Last updated 24 July 2024
Ubuntu priority
OpenStack Keystone Essex (2012.1) and Folsom (2012.2) does not properly handle EC2 tokens when the user role has been removed from a tenant, which allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for the removed user role.
Notes
jdstrand
Keystone on 11.10 is a pre-release version and unusable with other components such as nova and horizon
References
Related Ubuntu Security Notices (USN)
- USN-1641-1
- OpenStack Keystone vulnerabilities
- 28 November 2012