RHSA-2012:1378High
Red Hat Security Advisory: openstack-keystone security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2012-3542 — Keystone: Lack of authorization for adding users to tenants CVE-2012-4413 — OpenStack-Keystone: role revocation token issues CVE-2012-4456 — 2012.1.1: fails to validate tokens in Admin API CVE-2012-4457 — 2012.1.1: fails to raise Unauthorized user error for disabled tenant
🎯 Affected products6
- RHOS Essex Release
- openstack-keystone-0:2012.1.2-4.el6.noarch as a component of RHOS Essex Release
- openstack-keystone-0:2012.1.2-4.el6.src as a component of RHOS Essex Release
- openstack-keystone-doc-0:2012.1.2-4.el6.noarch as a component of RHOS Essex Release
- python-keystone-0:2012.1.2-4.el6.noarch as a component of RHOS Essex Release
- python-keystone-auth-token-0:2012.1.2-4.el6.noarch as a component of RHOS Essex Release
✅ Remediation
Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2012:1378
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=852510
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=855491
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=861179
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=861180
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2012/rhsa-2012_1378.json