High severityNVD Advisory· Published Oct 9, 2012· Updated Jun 16, 2026
CVE-2012-4456
CVE-2012-4456
Description
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
keystonePyPI | >= 2012.1, < 2012.1.2 | 2012.1.2 |
Affected products
3Patches
Vulnerability mechanics
References
17- www.openwall.com/lists/oss-security/2012/09/28/5nvdMailing ListPatchThird Party AdvisoryWEB
- bugs.launchpad.net/keystone/+bug/1006822nvdPatchThird Party AdvisoryWEB
- lists.launchpad.net/openstack/msg17034.htmlnvdPatchThird Party AdvisoryWEB
- secunia.com/advisories/50665nvdThird Party AdvisoryVendor Advisory
- www.securityfocus.com/bid/55716nvdThird Party AdvisoryVDB Entry
- bugs.launchpad.net/keystone/+bug/1006815nvdThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- exchange.xforce.ibmcloud.com/vulnerabilities/78944nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-mf98-r2gf-2x3wghsaADVISORY
- github.com/openstack/keystone/commit/14b136aed9d988f5a8f3e699bd4577c9b874d6c1nvdThird Party AdvisoryWEB
- github.com/openstack/keystone/commit/1d146f5c32e58a73a677d308370f147a3271c2cbnvdThird Party AdvisoryWEB
- github.com/openstack/keystone/commit/24df3adb3f50cbb5ada411bc67aba8a781e6a431nvdThird Party AdvisoryWEB
- github.com/openstack/keystone/commit/868054992faa45d6f42d822bf1588cb88d7c9ccbnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2012-4456ghsaADVISORY
- access.redhat.com/errata/RHSA-2012:1378ghsaWEB
- access.redhat.com/security/cve/CVE-2012-4456ghsaWEB
- web.archive.org/web/20121114024512/http://www.securityfocus.com/bid/55716ghsaWEB
News mentions
0No linked articles in our index yet.