---
title: "CVE-2012-5571\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-5571?format=md
keywords: index, follow
---

# CVE-2012-5571

Publication date 28 November 2012

Last updated 26 June 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.4 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2012-5571?format=md#impact-score)

Toggle side navigation

## Description

A flaw was found in OpenStack Keystone. This vulnerability allows remote
authenticated users to bypass intended authorization restrictions. This
occurs because OpenStack Keystone does not properly handle EC2 (Elastic
Compute Cloud) tokens when a user's role has been removed from a tenant. An
attacker can leverage a token associated with a removed user role to gain
unauthorized access.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2012-5571?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| keystone | 12.10 quantal | Fixed 2012.2-0ubuntu1.2 |
| 12.04 LTS precise | Fixed 2012.1+stable~20120824-a16a0ab9-0ubuntu2.3 |
| 11.10 oneiric | Ignored |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [jdstrand](https://launchpad.net/~jdstrand)

Keystone on 11.10 is a pre-release version and unusable with other
components such as nova and horizon

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.4 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | Low |
  | Integrity impact | Low |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.4 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5571)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-5571)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-5571)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-5571)

### Related Ubuntu Security Notices (USN)

+ [USN-1641-1](https://usn.ubuntu.com/USN-1641-1)
+ OpenStack Keystone vulnerabilities
+ 28 November 2012

### Other references

* <https://lists.launchpad.net/openstack/msg18999.html>
* <https://www.cve.org/CVERecord?id=CVE-2012-5571>
