OpenStack Security Advisory: 2012-015
CVE: CVE-2012-4456
Date: September 28, 2012
Title: Some actions in Keystone admin API do not validate token
Impact: High
Reporter: Jason Xu
Products: Keystone
Affects: Essex (prior to 2012.1.2), Folsom (prior to folsom-2
development milestone)
Description:
Jaxon Xu reported a vulnerability in Keystone. Two admin API actions
did not require a valid token. The first was listing roles for a
user. The second was the ability to get, create, and delete services.
Yet another set of keystone token validation problems. I could draw a pie chart of openstack vulnerabilities and it would look like a big round cheese wheel of token validation problems.