← Vulnerability feed

Vulnerability record · CVE-2012-4456 · published 9 October 2012

CVE-2012-4456: Openstack keystone improper authentication vulnerability

Openstack · Keystone

The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.

7.5 CVSS 2.0 High EPSS 4.0% · top 9.8% CWE-287 · Improper authentication
7.5CVSS 2.0 base score
4.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
24References
16 Jun 2026Last modified by NVD

Description

The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/50665 Third Party AdvisoryVendor Advisory
http://www.openwall.com/lists/oss-security/2012/09/28/5 Mailing ListPatchThird Party Advisory
http://www.securityfocus.com/bid/55716 Third Party AdvisoryVDB Entry
https://bugs.launchpad.net/keystone/+bug/1006815 Third Party Advisory
https://bugs.launchpad.net/keystone/+bug/1006822 PatchThird Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=861179 Issue TrackingThird Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/78944 Third Party AdvisoryVDB Entry
https://github.com/openstack/keystone/commit/14b136aed9d988f5a8f3e699bd4577c9b874d6c1 Third Party Advisory
https://github.com/openstack/keystone/commit/1d146f5c32e58a73a677d308370f147a3271c2cb Third Party Advisory
https://github.com/openstack/keystone/commit/24df3adb3f50cbb5ada411bc67aba8a781e6a431 Third Party Advisory
https://github.com/openstack/keystone/commit/868054992faa45d6f42d822bf1588cb88d7c9ccb Third Party Advisory
https://lists.launchpad.net/openstack/msg17034.html PatchThird Party Advisory
http://secunia.com/advisories/50665 Third Party AdvisoryVendor Advisory
http://www.openwall.com/lists/oss-security/2012/09/28/5 Mailing ListPatchThird Party Advisory
http://www.securityfocus.com/bid/55716 Third Party AdvisoryVDB Entry
https://bugs.launchpad.net/keystone/+bug/1006815 Third Party Advisory
https://bugs.launchpad.net/keystone/+bug/1006822 PatchThird Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=861179 Issue TrackingThird Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/78944 Third Party AdvisoryVDB Entry
https://github.com/openstack/keystone/commit/14b136aed9d988f5a8f3e699bd4577c9b874d6c1 Third Party Advisory
https://github.com/openstack/keystone/commit/1d146f5c32e58a73a677d308370f147a3271c2cb Third Party Advisory
https://github.com/openstack/keystone/commit/24df3adb3f50cbb5ada411bc67aba8a781e6a431 Third Party Advisory
https://github.com/openstack/keystone/commit/868054992faa45d6f42d822bf1588cb88d7c9ccb Third Party Advisory
https://lists.launchpad.net/openstack/msg17034.html PatchThird Party Advisory

Track CVE-2012-4456 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-42998Openstack keystone incorrect authorization vulnerabilityAn issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user …EPSS 0.40%8.8CVE-2026-42999Openstack keystone incorrect authorization vulnerabilityAn issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON re…EPSS 0.42%8.8CVE-2026-43000Openstack keystone incorrect authorization vulnerabilityAn issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker wi…EPSS 0.43%8.8CVE-2020-12689Openstack keystone improper privilege management vulnerabilityAn issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application crede…EPSS 1.6%8.8CVE-2020-12690Openstack keystone insufficient session expiration vulnerabilityAn issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. T…EPSS 1.9%8.8CVE-2020-12691Openstack keystone incorrect authorization vulnerabilityAn issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a pro…EPSS 4.9%8.8CVE-2019-19687Openstack keystone insufficiently protected credentials vulnerabilityOpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any c…EPSS 1.8%8.1CVE-2026-44394Openstack keystone incorrect authorization vulnerabilityAn issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's…EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2012-4456), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.