CVE-2012-4457: Openstack Keystone

Medium severity, CVSS 4.0. EPSS: 2.3% chance of exploitation in the next 30 days.

OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.

Affected products

  • Openstack Keystone: from 2012.1, before 2012.1.2 (fixed in 2012.1.2); version 2012.2 only

Published 2012-10-09. Last modified 2026-06-16.