Loading...
Loading...
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.
October 9, 2012
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2012-4456
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.