VDB
CVE-2012-5571
CVE-2012-5571
PUBLISHED
CVSS 3.5 LOW
OpenStack Keystone intended authorization restrictions bypass
EPSS 2.05% · 79.4th percentile
Risk Scores
CVSS 2.0
3.5
EPSS Score
2.05%
79.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PyPI | keystone | 0 |
| PyPI | Keystone | 0 |
| openstack | folsom | 2012.2 |
| n/a | n/a | n/a |
| openstack | essex | 2012.1 |
Timeline
- Dec 18, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 9, 2023 EPSS Score
- Feb 13, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- https://github.com/openstack/keystone/commit/37308dd4f3e33f7bd0f71d83fd51734d1870713b url
- https://github.com/openstack/keystone/commit/8735009dc5b895db265a1cd573f39f4acfca2a19 url
- RHSA-2012:1556 vendor-advisory
- [oss-security] 20121128 [OSSA 2012-018] EC2-style credentials invalidation issue (CVE-2012-5571) mailing-list
- USN-1641-1 vendor-advisory
- keystone-tenant-sec-bypass(80333) vdb
- https://github.com/openstack/keystone/commit/9d68b40cb9ea818c48152e6c712ff41586ad9653 url
- 51423 third-party-advisory
- 51436 third-party-advisory
- FEDORA-2012-19341 vendor-advisory
- RHSA-2012:1557 vendor-advisory
- https://bugs.launchpad.net/keystone/+bug/1064914 url
- [oss-security] 20121128 [OSSA 2012-019] Extension of token validity through token chaining (CVE-2012-5563) mailing-list
- 56726 vdb
- https://github.com/openstack/keystone package
- https://nvd.nist.gov/vuln/detail/CVE-2012-5571 advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/keystone/PYSEC-2012-35.yaml url