CVE-2012-5563: Medium severity red hat openstack folsom vulnerability
OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5563?
CVE-2012-5563 is considered a high severity vulnerability due to its potential to allow unauthorized access through token chaining.
How do I fix CVE-2012-5563?
To fix CVE-2012-5563, upgrade OpenStack Keystone to version 8.0.0 or later.
Who is affected by CVE-2012-5563?
CVE-2012-5563 affects users running OpenStack Folsom version 2012.2 and earlier versions of Keystone.
What can happen if CVE-2012-5563 is exploited?
Exploiting CVE-2012-5563 allows remote authenticated users to bypass authorization restrictions, potentially leading to unauthorized data access.
Is CVE-2012-5563 a known issue in OpenStack?
Yes, CVE-2012-5563 is recognized as a vulnerability in OpenStack Keystone, linked to a regression in CVE-2012-3426.