CVE-2012-5563
Title: Openstack Folsom
Other
Proof Of Concept
No public PoC currently indexed for CVE-2012-5563.
CWE Category
CWE-255
Published Date
Dec 18, 2012
Modified Date
Jun 16, 2026
Exploit Status
Not Found
Score
4.0
CVSS v2.0
Exploit Probability (EPSS)
2.84%
Vulnerability Summary
CVE-2012-5563: OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.
Impacted Vendors
Reference Links
http://rhn.redhat.com/errata/RHSA-2012-1557.html
http://secunia.com/advisories/51423
http://secunia.com/advisories/51436
http://www.openwall.com/lists/oss-security/2012/11/28/5
http://www.openwall.com/lists/oss-security/2012/11/28/6
http://www.securityfocus.com/bid/56727
http://www.ubuntu.com/usn/USN-1641-1
https://bugs.launchpad.net/keystone/+bug/1079216
https://exchange.xforce.ibmcloud.com/vulnerabilities/80370
https://github.com/openstack/keystone/commit/38c7e46a640a94da4da89a39a5a1ea9c081f1eb5
https://github.com/openstack/keystone/commit/f9d4766249a72d8f88d75dcf1575b28dd3496681
http://rhn.redhat.com/errata/RHSA-2012-1557.html
http://secunia.com/advisories/51423
http://secunia.com/advisories/51436
http://www.openwall.com/lists/oss-security/2012/11/28/5
http://www.openwall.com/lists/oss-security/2012/11/28/6
http://www.securityfocus.com/bid/56727
http://www.ubuntu.com/usn/USN-1641-1
https://bugs.launchpad.net/keystone/+bug/1079216
https://exchange.xforce.ibmcloud.com/vulnerabilities/80370
https://github.com/openstack/keystone/commit/38c7e46a640a94da4da89a39a5a1ea9c081f1eb5
https://github.com/openstack/keystone/commit/f9d4766249a72d8f88d75dcf1575b28dd3496681
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
4.0
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:L/Au:S/C:N/I:P/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2012-5563 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:L/Au:S/C:N/I:P/A:N
Affected Stack
No specific products linked.