Back

HIGH

Keystone: Lack of authorization for adding users to tenants

Published Sep 5, 2012

Description

OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 5, 2012
Updated Aug 6, 2024
Reserved Jun 14, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Aug 30, 2012
GHSA-GF2Q-J2QQ-PJF2