[Openstack-announce] [OSSA 2012-016] Token authorization for a user in a disabled tenant is allowed (CVE-2012-4457)

Russell Bryant rbryant at redhat.com
Fri Sep 28 20:50:47 UTC 2012

OpenStack Security Advisory: 2012-016
CVE: CVE-2012-4457
Date: September 28, 2012
Title: Token authorization for a user in a disabled tenant is allowed
Impact: High
Reporter: Rohit Karajgi (NTT Data)
Affects: Essex (prior to 2012.1.2), Folsom (prior to folsom-3
development milestone)

Rohit Karajgi reported a vulnerability in Keystone. It was possible to
get a token that is authorized for a disabled tenant. Once the token is
established with authorization on the tenant, keystone would respond 200
OK to token validation requests from other OpenStack services, allowing
the user to work with the tenant's resources.

Folsom fix: (Included in 2012.2)

Essex fix: (Included in 2012.1.2)


Russell Bryant
OpenStack Vulnerability Management Team

More information about the OpenStack-announce mailing list