CVE-2012-3426

medium
Published 2012-07-31 · Modified 2024-11-22
CVSS v3
CVSS v2
4.9
VIR risk
4.9

Description

OpenStack Keystone token expiration issues

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-3426

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://launchpad.net/keystone/essex/2012.1.1/+download/keystone-2012.1.1.tar.gz

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.openwall.com/lists/oss-security/2012/07/27/4

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://github.com/openstack/keystone/commit/ea03d05ed5de0c015042876100d37a6a14bf56de

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://github.com/openstack/keystone/commit/628149b3dc6b58b91fd08e6ca8d91c728ccb8626

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://github.com/openstack/keystone/commit/375838cfceb88cacc312ff6564e64eb18ee6a355

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2012.1.1-1
debian debianbullseyefixed2012.1.1-1
debian debianforkyfixed2012.1.1-1
debian debiansidfixed2012.1.1-1
debian debiantrixiefixed2012.1.1-1

Package impact

EcosystemPackageVulnerableFixed
python PyPIkeystone<8.0.0a08.0.0a0

Application impact

VendorProductVersionsFixed
openstackessex
openstackhorizonfolsom-1
openstackkeystone2012.1
openstackkeystone2012.1.1

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.