CVE-2012-3426 - CVE House
Back to Database
Status published Medium CVE-2012-3426

OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before...

Vulnerability Description

OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-3426

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

essex, horizon, keystone
Vulnerable Versions:
folsom-1, 2012.1, 2012.1.1

Timeline

Official Publish: July 31st, 2012
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.