{"id":"CVE-2012-4413","aliases":["GHSA-mrxv-65rv-6hxq","PYSEC-2026-833"],"url":"https://o3.security/vulnerability/CVE-2012-4413","summary":"OpenStack Keystone does not invalidate existing tokens when granting or revoking roles","details":"OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.","published":"2012-09-18T17:55:07Z","modified":"2026-07-07T11:56:45.925496659Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"keystone","fixedVersion":"2012.1.3"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/50531"},{"type":"ADVISORY","url":"http://secunia.com/advisories/50590"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-1564-1"},{"type":"WEB","url":"http://osvdb.org/85484"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/09/12/7"},{"type":"WEB","url":"http://www.securityfocus.com/bid/55524"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/78478"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T11:56:45.925496659Z"}}