CVE-2012-5571

OpenStack Keystone Essex (2012.1) and Folsom (2012.2) does not properly handle EC2 tokens when the user role has been removed from a tenant, which allows remote authenticated users to bypass intended authorization restrictions by leveraging a token for the removed user role.

Scoring

Severity
MEDIUM
CVSS base score
5.4
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS probability
0.17%
CWE
CWE-639
Published
2012-12-18
Last modified
2026-04-07

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs