Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2012-3426

19
FAUCET Score

CVE-2012-3426 describes a token expiration vulnerability in OpenStack Keystone versions before 2012.1.1, impacting OpenStack Folsom and Essex. Authenticated attackers could bypass authorization by chaining tokens, using tokens from disabled accounts, or tokens associated with changed passwords. With a CVSS score of 4.9 (AV:N/AC:M/Au:S/C:P/I:P/A:N), this medium-severity flaw allows partial confidentiality and integrity compromise with moderate attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion for this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:a:openstack:essex:*:*:*:*:*:*:*:*
folsom-1CPE matchmatch criteria
cpe:2.3:a:openstack:horizon:folsom-1:*:*:*:*:*:*:*
2012.1CPE matchmatch criteria
cpe:2.3:a:openstack:keystone:2012.1:*:*:*:*:*:*:*
2012.1.1CPE matchmatch criteria
cpe:2.3:a:openstack:keystone:2012.1.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.9MEDIUM

AV:N/AC:M/Au:S/C:P/I:P/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
SINGLE
Exploitability Score
6.8
Impact Score
4.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.28%
Probability of exploitation in next 30 days
EPSS Percentile
81.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0228 is in the 89th percentile among its peer group of 1,424 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: KeystoneFixed in: 8.0.0a0
ubuntupatch availablevia nvd_reference
View patch

Vendor Advisories (1)

pipGHSA-xp97-6w7r-4cjcmedium

OpenStack Keystone token expiration issues

May 17, 2022

References

github.com / openstack/keystone/commit/29e74e73a6e51cffc0371b32354558391826a4aa
github.com / openstack/keystone/commit/375838cfceb88cacc312ff6564e64eb18ee6a355
Patch
github.com / openstack/keystone/commit/628149b3dc6b58b91fd08e6ca8d91c728ccb8626
ExploitPatch
github.com / openstack/keystone/commit/a67b24878a6156eab17b9098fa649f0279256f5d
github.com / openstack/keystone/commit/d9600434da14976463a0bd03abd8e0309f0db454
github.com / openstack/keystone/commit/ea03d05ed5de0c015042876100d37a6a14bf56de
ExploitPatch
bugs.launchpad.net / keystone/+bug/996595
bugs.launchpad.net / keystone/+bug/997194
bugs.launchpad.net / keystone/+bug/998185
secunia.com / advisories/50045
secunia.com / advisories/50494
launchpad.net / keystone/essex/2012.1.1/+download/keystone-2012.1.1.tar.gz
Patch
openwall.com / lists/oss-security/2012/07/27/4
Patch
ubuntu.com / usn/USN-1552-1