Oval Definition:oval:com.ubuntu.precise:def:20124413000
Revision Date:2012-09-18Version:1
Title:CVE-2012-4413 on Ubuntu 12.04 LTS (precise) - medium.
Description:OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. Dolph Mathews discovered that when roles are granted and revoked to users in Keystone, pre-existing tokens were not updated or invalidated to take the new roles into account. An attacker could use this to continue to access resources that have been revoked.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2012-4413
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND The 'keystone' package in precise was vulnerable but has been fixed (note: '2012.1+stable~20120824-a16a0ab9-0ubuntu2.2').
  • BACK