CVE-2020-12692

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-12692
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-12692.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-12692
Aliases
Downstream
Published
2020-05-07T00:15:10Z
Modified
2025-10-21T02:36:21Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an OpenStack token an unlimited number of times.

References

Affected packages

Git / github.com/openstack/keystone

Affected ranges

Type
GIT
Repo
https://github.com/openstack/keystone
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed