Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2012-4457

17
FAUCET Score

CVE-2012-4457 affects OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3, allowing authenticated users to access resources of disabled tenants by requesting a token. This vulnerability has a CVSS score of 4.0, indicating a low severity with potential for partial confidentiality impact, requiring authentication over a network with low attack complexity. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2012.1, < 2012.1.2CPE matchmatch criteria
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
2012.2CPE matchmatch criteria
cpe:2.3:a:openstack:keystone:2012.2:milestone1:*:*:*:*:*:*
2012.2CPE matchmatch criteria
cpe:2.3:a:openstack:keystone:2012.2:milestone2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.0MEDIUM

AV:N/AC:L/Au:S/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
SINGLE
Exploitability Score
8.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.27%
Probability of exploitation in next 30 days
EPSS Percentile
81.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0227 is in the 93rd percentile among its peer group of 21,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

pippatch availablevia ghsa
Product: KeystoneFixed in: 8.0.0a0
redhatpatch availablevia redhat_api
Product: OpenStack Essex for RHEL 6Fixed in: openstack-keystone-0:2012.1.2-4.el6
View patch

Vendor Advisories (2)

pipGHSA-x8h4-xf47-pqc3medium

OpenStack Keystone Token authorization for a user in a disabled tenant is allowed

May 14, 2022
redhatCVE-2012-4457Moderate

2012.1.1: fails to raise Unauthorized user error for disabled tenant

May 26, 2012

References

bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
secunia.com / advisories/50665
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/78947
Third Party AdvisoryVDB Entry
github.com / openstack/keystone/commit/4ebfdfaf23c6da8e3c182bf3ec2cb2b7132ef685
Third Party Advisory
github.com / openstack/keystone/commit/5373601bbdda10f879c08af1698852142b75f8d5
Third Party Advisory
lists.launchpad.net / openstack/msg17035.html
Third Party Advisory
openwall.com / lists/oss-security/2012/09/28/6
Mailing ListThird Party Advisory
securityfocus.com / bid/55716
Third Party AdvisoryVDB Entry