ossa/OSSA-2012-016.yaml

53 lines
1.3 KiB
YAML

advisory-date: 2012-09-28
advisory-id: OSSA-2012-016
advisory-title: 'Token authorization for a user in a disabled tenant is allowed'
advisory-description: 'Rohit Karajgi reported a vulnerability in Keystone. It was
possible to get a token that is authorized for a disabled tenant. Once the token
is established with authorization on the tenant, keystone would respond 200 OK to
token validation requests from other OpenStack services, allowing the user to work with
the tenant''s resources. '
advisory-reference: https://lists.launchpad.net/openstack/msg17035.html
affected-products:
- product: keystone
version: TODO
vulnerabilities:
- cve-id: CVE-2012-4457
impact-assessment:
source: 'Red Hat Product Security'
rating: moderate
assessment:
type: CVSS2
score: 4.0
detail: AV:N/AC:L/Au:S/C:N/I:P/A:N
classification:
source: 'Red Hat Product Security'
type: CWE
detail: TODO
reporters:
- name: 'Rohit Karajgi'
affiliation: 'NTT Data'
reported:
- CVE-2012-4457
notes:
issues:
issue-tracking-system-url: https://launchpad.net/bugs/{id}
issue-tracking-system-type : 'launchpad'
issue-id:
- 988920
reviews:
review-system-url: https://review.openstack.org/#/c/{id}
review-system-type: 'gerrit'
review-id:
- 9862
- 10534