CVE-2012-4457

EPSS 0.56%

OpenStack Keystone Token authorization for a user in a disabled tenant is allowed

發布日:2022/5/14修改日:2026/4/28

描述

OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.

受影響套件(2)

參考連結(11)