Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2012-4456

The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create, or delete arbitrary services.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.04
EPSS Ranking 87.7%
CVSS Severity
CVSS v2 Score 7.5
References
Products affected by CVE-2012-4456


Contact Us

Shodan ® - All rights reserved