openstack essex CVE-2012-3542 vulnerability in OpenStack Products
Published on September 5, 2012

OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540.

Vendor Advisory NVD


Products Associated with CVE-2012-3542

stack.watch emails you whenever new vulnerabilities are published in OpenStack Essex or OpenStack Horizon. Just hit a watch button to start following.

 
 

Exploit Probability

EPSS
1.95%
Percentile
83.22%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.