CVE-2012-4413: Openstack Keystone
Medium severity, CVSS 4.0. EPSS: 1.9% chance of exploitation in the next 30 days.
OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.
Affected products
- Openstack Keystone: version 2012.1.3 only
Published 2012-09-18. Last modified 2026-06-16.