CVE-2012-5571

medium
Published 2012-12-18 · Modified 2026-04-07
CVSS v3
5.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS v2
3.5
VIR risk
5.4

Description

OpenStack Keystone intended authorization restrictions bypass

Predictions

Exploit likelihood
64%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-5571

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/openstack/keystone/commit/9d68b40cb9ea818c48152e6c712ff41586ad9653

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/openstack/keystone/commit/8735009dc5b895db265a1cd573f39f4acfca2a19

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/openstack/keystone/commit/37308dd4f3e33f7bd0f71d83fd51734d1870713b

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugs.launchpad.net/keystone/+bug/1064914

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.openwall.com/lists/oss-security/2012/11/28/6

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.openwall.com/lists/oss-security/2012/11/28/5

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/51436

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/51423

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2012.1.1-11
debian debianbullseyefixed2012.1.1-11
debian debianforkyfixed2012.1.1-11
debian debiansidfixed2012.1.1-11
debian debiantrixiefixed2012.1.1-11

Package impact

EcosystemPackageVulnerableFixed
python PyPIkeystone<8.0.0a08.0.0a0

Application impact

VendorProductVersionsFixed
openstackessex2012.1
openstackfolsom2012.2

References

CWEs

CWE-639 CWE-255

Verify integrity in audit chain (admin only). AS-IS.