Total vulnerabilities in the database
OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the tenant.
Software | From | Fixed in |
---|---|---|
openstack / keystone | 2012.2-milestone1 | 2012.2-milestone1.x |
openstack / keystone | 2012.1 | 2012.1.2 |
openstack / keystone | 2012.2-milestone2 | 2012.2-milestone2.x |