{"id":"CVE-2012-4413","details":"OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.","aliases":["GHSA-mrxv-65rv-6hxq","PYSEC-2026-833"],"modified":"2026-07-07T11:56:45.925496659Z","published":"2012-09-18T17:55:07Z","related":["CGA-7648-v244-356c"],"references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/50531"},{"type":"ADVISORY","url":"http://secunia.com/advisories/50590"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-1564-1"},{"type":"WEB","url":"http://osvdb.org/85484"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2012/09/12/7"},{"type":"WEB","url":"http://www.securityfocus.com/bid/55524"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/78478"}],"schema_version":"1.7.5"}