Search/CVE-2012-3426
CVE

CVE-2012-3426

OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.

CVSS v3.1
EPSS
2.28%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Connections
4 relationships
Timeline
disclosure → media coverage
Jul 31, 2012
Disclosure — published as a CVE record. · last revised by NVD Apr 29, 2026