Vulnerability Description
A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly handle EC2 (Elastic Compute Cloud) tokens when a user's role has been removed from a tenant. An attacker can leverage a token associated with a removed user role to gain unauthorized access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openstack | Essex | 2012.1 |
| Openstack | Folsom | 2012.2 |
Related Weaknesses (CWE)
References
- http://lists.fedoraproject.org/pipermail/package-announce/2012-December/094286.h
- http://rhn.redhat.com/errata/RHSA-2012-1556.html
- http://rhn.redhat.com/errata/RHSA-2012-1557.html
- http://secunia.com/advisories/51423Vendor Advisory
- http://secunia.com/advisories/51436Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/11/28/5Patch
- http://www.openwall.com/lists/oss-security/2012/11/28/6Patch
- http://www.securityfocus.com/bid/56726
- http://www.ubuntu.com/usn/USN-1641-1
- https://access.redhat.com/security/cve/CVE-2012-5571
- https://bugs.launchpad.net/keystone/+bug/1064914Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80333
- https://github.com/openstack/keystone/commit/37308dd4f3e33f7bd0f71d83fd51734d187Patch
- https://github.com/openstack/keystone/commit/8735009dc5b895db265a1cd573f39f4acfcPatch
- https://github.com/openstack/keystone/commit/9d68b40cb9ea818c48152e6c712ff41586aPatch
FAQ
What is CVE-2012-5571?
CVE-2012-5571 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly han...
How severe is CVE-2012-5571?
CVE-2012-5571 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-5571?
Check the references section above for vendor advisories and patch information. Affected products include: Openstack Essex, Openstack Folsom.