Back

HIGH

OpenStack: Keystone extension of token validity through token chaining

Published Dec 18, 2012

Description

OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 18, 2012
Updated Aug 6, 2024
Reserved Oct 24, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Nov 28, 2012
GHSA-W66P-78G4-MR7G