Back

HIGH

2012.1.1: fails to validate tokens in Admin API

Published Oct 9, 2012

Description

The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 9, 2012
Updated Aug 6, 2024
Reserved Aug 21, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date May 31, 2012
GHSA-MF98-R2GF-2X3W