CVE-2012-4413

medium
Published 2012-09-18 · Modified 2024-12-04
CVSS v3
CVSS v2
4.0
VIR risk
4.0

Description

OpenStack Keystone does not invalidate existing tokens when granting or revoking roles

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-4413

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/50590

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/50531

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2012.1.1-6
debian debianbullseyefixed2012.1.1-6
debian debianforkyfixed2012.1.1-6
debian debiansidfixed2012.1.1-6
debian debiantrixiefixed2012.1.1-6

Package impact

EcosystemPackageVulnerableFixed
python PyPIkeystone<2012.1.32012.1.3

Application impact

VendorProductVersionsFixed
openstackkeystone2012.1.3

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.