OpenStack Keystone CVE-2012-5571 Security Bypass Vulnerability
BID:56726
Info
OpenStack Keystone CVE-2012-5571 Security Bypass Vulnerability
| Bugtraq ID: | 56726 |
| Class: | Design Error |
| CVE: |
CVE-2012-5571 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2012 12:00AM |
| Updated: | Apr 13 2015 09:52PM |
| Credit: | Vijaya Erukala |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.10 i386 Ubuntu Ubuntu Linux 12.10 amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Redhat OpenStack Folsom 0 Redhat OpenStack Essex 0 OpenStack Keystone 2012.1.1 OpenStack Keystone 2012.1 OpenStack Keystone 2012.2 OpenStack Keystone 2012.1.3 OpenStack Keystone 2012.1.2 |
| Not Vulnerable: | |
Exploit / POC
Solution / Fix
OpenStack Keystone CVE-2012-5571 Security Bypass Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
OpenStack Keystone CVE-2012-5571 Security Bypass Vulnerability
References:
References:
- [OSSA 2012-018] EC2-style credentials invalidation issue (CVE-2012-5571) (oss-security)
- Bug 880399 - CVE-2012-5571 OpenStack: Keystone EC2-style credentials invalidatio (Red Hat Bugzilla)
- Ensures User is member of tenant in ec2 validation (GitHub)
- OpenStack Keystone Homepage (OpenStack )
- Removing user from a tenant isn't invalidating user access to tenant (OpenStack)
- Moderate: openstack-keystone security, bug fix, and enhancement update (Red Hat)
- Moderate: openstack-keystone security, bug fix, and enhancement update (Red Hat)