OSSA-2012-016: Token authorization for a user in a disabled tenant is allowed

OSSA-2012-016: Token authorization for a user in a disabled tenant is allowed

Date:September 28, 2012
CVE:CVE-2012-4457

Affects

  • Keystone: Essex (prior to 2012.1.2), Folsom (prior to folsom-3 development milestone)

Description

Rohit Karajgi reported a vulnerability in Keystone. It was possible to get a token that is authorized for a disabled tenant. Once the token is established with authorization on the tenant, keystone would respond 200 OK to token validation requests from other OpenStack services, allowing the user to work with the tenant’s resources.

Credits

  • Rohit Karajgi from NTT Data (CVE-2012-4457)
Creative Commons Attribution 3.0 License

Except where otherwise noted, this document is licensed under Creative Commons Attribution 3.0 License. See all OpenStack Legal Documents.