High severity8.8NVD Advisory· Published May 7, 2020· Updated Jun 17, 2026
CVE-2020-12690
CVE-2020-12690
Description
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a keystone token, the keystone token contains every role assignment the creator had for the project. This results in the provided keystone token having more role assignments than the creator intended, possibly giving unintended escalated access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
keystonePyPI | < 15.0.1 | 15.0.1 |
keystonePyPI | >= 16.0.0.0rc1, < 16.0.0 | 16.0.0 |
Affected products
4- OpenStack/Keystonedescription
Patches
Vulnerability mechanics
References
12- bugs.launchpad.net/keystone/+bug/1873290nvdPatchThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2020/05/07/3nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-6m8p-x4qw-gh5jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-12690ghsaADVISORY
- security.openstack.org/ossa/OSSA-2020-005.htmlnvdVendor AdvisoryWEB
- www.openwall.com/lists/oss-security/2020/05/06/6nvdMailing ListThird Party AdvisoryWEB
- github.com/pypa/advisory-database/tree/main/vulns/keystone/PYSEC-2020-54.yamlghsaWEB
- lists.apache.org/thread.html/re4ffc55cd2f1b55a26e07c83b3c22c3fe4bae6054d000a57fb48d8c2@%3Ccommits.druid.apache.org%3EghsaWEB
- usn.ubuntu.com/4480-1ghsaWEB
- lists.apache.org/thread.html/re237267da268c690df5e1c6ea6a38a7fc11617725e8049490f58a6fa%40%3Ccommits.druid.apache.org%3Envd
- lists.apache.org/thread.html/re4ffc55cd2f1b55a26e07c83b3c22c3fe4bae6054d000a57fb48d8c2%40%3Ccommits.druid.apache.org%3Envd
- usn.ubuntu.com/4480-1/nvd
News mentions
0No linked articles in our index yet.