CVE-2012-4457

Publication date 9 October 2012

Last updated 24 July 2024


Ubuntu priority

OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.

Read the notes from the security team

Status

Package Ubuntu Release Status
keystone 12.10 quantal
Not affected
12.04 LTS precise
Fixed 2012.1+stable~20120824-a16a0ab9-0ubuntu2
11.10 oneiric Ignored
11.04 natty Not in release
10.04 LTS lucid Not in release
8.04 LTS hardy Not in release

Notes


jdstrand

Keystone on 11.10 is a pre-release version and unusable with other components such as nova and horizon