CVE-2012-5571
OpenStack Keystone intended authorization restrictions bypass
5.4
MEDIUM
CVSS 3.1
EPSS 2.0%
描述
A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly handle EC2 (Elastic Compute Cloud) tokens when a user's role has been removed from a tenant. An attacker can leverage a token associated with a removed user role to gain unauthorized access.
如何修補 CVE-2012-5571
要修補 CVE-2012-5571,請將受影響套件升級到下列已修補版本。
- —升級至 2012.1.1-11 或更新版本
- —升級至 8.0.0a0 或更新版本
- —升級至 37308dd4f3e33f7bd0f71d83fd51734d1870713b 或更新版本
CVE-2012-5571 正在被利用嗎?
低 — EPSS 為 2.0%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 2012.1.1-11
- from 0, < 8.0.0a0
- from 0, < 37308dd4f3e33f7bd0f71d83fd51734d1870713b, < 8735009dc5b895db265a1cd573f39f4acfca2a19, < 9d68b40cb9ea818c48152e6c712ff41586ad9653 | from 0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |