ossa/ossa/OSSA-2012-016.yaml

58 lines
1.3 KiB
YAML

date: 2012-09-28
id: OSSA-2012-016
title: 'Token authorization for a user in a disabled tenant is allowed'
description: 'Rohit Karajgi reported a vulnerability in Keystone. It was possible
to get a token that is authorized for a disabled tenant. Once the token is established
with authorization on the tenant, keystone would respond 200 OK to token validation
requests from other OpenStack services, allowing the user to work with the tenant''s
resources. '
reference: https://lists.launchpad.net/openstack/msg17035.html
affected-products:
- product: keystone
version: Essex (prior to 2012.1.2), Folsom (prior to folsom-3 development milestone)
vulnerabilities:
- cve-id: CVE-2012-4457
impact-assessment:
source: 'Red Hat Product Security'
rating: moderate
assessment:
type: CVSS2
score: 4.0
detail: AV:N/AC:L/Au:S/C:N/I:P/A:N
classification:
source: 'Red Hat Product Security'
type: CWE
detail: TODO
reporters:
- name: 'Rohit Karajgi'
affiliation: 'NTT Data'
reported:
- CVE-2012-4457
issues:
links:
- https://launchpad.net/bugs/988920
type: launchpad
reviews:
folsom:
- https://review.openstack.org/#/c/9862
essex:
- https://review.openstack.org/#/c/10534
type: gerrit