CVE-2012-4456High▾ TwilightOpenStack Keystone Improper Authentication vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
4.0%
4.0% → 4.0%
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.
keystone >= 2012.1, < 2012.1.2Upgrade to a patched release:
keystone 2012.1.2Connected by shared product, vendor, weakness, or advisory.
CVE-2012-3542High· 7.5OpenStack Keystone Allows Remote User Account Creation
CVE-2012-4457MediumOpenStack Keystone Token authorization for a user in a disabled tenant is allowed
CVE-2026-44394Medium· 6.0OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
CVE-2026-43000Medium· 6.0OpenStack Keystone has an Incorrect Authorization issue
CVE-2012-4413MediumOpenStack Keystone does not invalidate existing tokens when granting or revoking roles
CVE-2015-3646MediumOpenStack Keystone Logs Passwords