CVE-2012-3426
Summary
| CVE | CVE-2012-3426 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-07-31 10:45:42 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| launchpad.net/keystone/essex/2012.1.1/+download/keystone-2012.1.1.tar.gz | af854a3a-2127-422b-91ae-364da2661108 | launchpad.net | Patch |
| Invalidate user tokens when a user is disabled · openstack/keystone@d960043 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| Invalidate user tokens when password is changed · openstack/keystone@a67b248 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| Bug #997194 “[OSSA 2012-010] Tokens remain valid after a user ac...” : Bugs : Keystone | af854a3a-2127-422b-91ae-364da2661108 | bugs.launchpad.net | |
| Bug #998185 “[OSSA 2012-010] Once a token is created/distributed...” : Bugs : OpenStack Identity (keystone) | af854a3a-2127-422b-91ae-364da2661108 | bugs.launchpad.net | |
| oss-security - [OSSA 2012-010] Various Keystone token expiration issues (CVE-2012-3426) | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Patch |
| Carrying over token expiry time when token chaining · openstack/keystone@375838c · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Patch |
| Carrying over token expiry time when token chaining · openstack/keystone@29e74e7 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| Bug #996595 “[OSSA 2012-010] Following a password compromise and...” : Bugs : Keystone | af854a3a-2127-422b-91ae-364da2661108 | bugs.launchpad.net | |
| Invalidate user tokens when password is changed · openstack/keystone@ea03d05 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Patch |
| Security Advisory SA50045 - OpenStack Keystone Token Expiration Security Bypass Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| USN-1552-1: OpenStack Keystone vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Invalidate user tokens when a user is disabled · openstack/keystone@628149b · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Patch |
| Security Advisory SA50494 - Ubuntu update for keystone - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 996738 Python (Pip) Security Update for Keystone (GHSA-xp97-6w7r-4cjc)