RHSA-2012:1378High

Red Hat Security Advisory: openstack-keystone security update

Published
October 16, 2012
Last Modified
July 30, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2012-3542 — Keystone: Lack of authorization for adding users to tenants CVE-2012-4413 — OpenStack-Keystone: role revocation token issues CVE-2012-4456 — 2012.1.1: fails to validate tokens in Admin API CVE-2012-4457 — 2012.1.1: fails to raise Unauthorized user error for disabled tenant

🎯 Affected products6

  • RHOS Essex Release
  • openstack-keystone-0:2012.1.2-4.el6.noarch as a component of RHOS Essex Release
  • openstack-keystone-0:2012.1.2-4.el6.src as a component of RHOS Essex Release
  • openstack-keystone-doc-0:2012.1.2-4.el6.noarch as a component of RHOS Essex Release
  • python-keystone-0:2012.1.2-4.el6.noarch as a component of RHOS Essex Release
  • python-keystone-auth-token-0:2012.1.2-4.el6.noarch as a component of RHOS Essex Release

✅ Remediation

Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258

🔗 References (7)