CVE-2020-12692: Canonical Ubuntu Linux

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an OpenStack token an unlimited number of times.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only
  • Openstack Keystone: before 15.0.1 (fixed in 15.0.1); version 16.0.0 only

Published 2020-05-07. Last modified 2026-06-17.