{"id":"CVE-2020-12691","details":"An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a project that they have a specified role on, and then perform an update to the credential user and project, allowing them to masquerade as another user. This potentially allows a malicious user to act as the admin on a project another user has the admin role on, which can effectively grant that user global admin privileges.","aliases":["GHSA-4427-7f3w-mqv6","PYSEC-2020-55"],"modified":"2026-07-08T05:55:19.180602139Z","published":"2020-05-07T00:15:10.957Z","database_specific":{"unresolved_ranges":[{"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux","cpes":["cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"],"extracted_events":[{"introduced":"18.04"},{"last_affected":"18.04"}]}]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/re237267da268c690df5e1c6ea6a38a7fc11617725e8049490f58a6fa%40%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/re4ffc55cd2f1b55a26e07c83b3c22c3fe4bae6054d000a57fb48d8c2%40%3Ccommits.druid.apache.org%3E"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2020/05/07/2"},{"type":"ADVISORY","url":"https://security.openstack.org/ossa/OSSA-2020-004.html"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4480-1/"},{"type":"ADVISORY","url":"https://www.openwall.com/lists/oss-security/2020/05/06/5"},{"type":"FIX","url":"https://bugs.launchpad.net/keystone/+bug/1872733"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openstack/keystone","events":[{"introduced":"0"},{"fixed":"95b2bbeab113d9f04d1c81f7f1b48bf692bce979"},{"introduced":"dc9e9e32dfbf9fd9c58f9f8e2b35f0bcfd62328e"},{"last_affected":"dc9e9e32dfbf9fd9c58f9f8e2b35f0bcfd62328e"}],"database_specific":{"cpe":["cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*","cpe:2.3:a:openstack:keystone:16.0.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"15.0.1"},{"introduced":"16.0.0"},{"last_affected":"16.0.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["16.0.0","16.0.0.0rc2","15.0.0.0rc2","15.0.0","15.0.0.0rc1","14.0.0.0rc1","14.0.0.0b2","14.0.0.0b1","13.0.0.0rc1","13.0.0.0b3","13.0.0.0b2","13.0.0.0b1","12.0.0.0rc1","12.0.0.0b3","12.0.0.0b2","12.0.0.0b1","11.0.0.0rc1","11.0.0","11.0.0.0b3","11.0.0.0b2","11.0.0.0b1","10.0.0.0rc1","10.0.0.0b3","10.0.0.0b2","10.0.0.0b1","9.0.0.0rc1","9.0.0.0b3","9.0.0.0b2","9.0.0.0b1","8.0.0.0rc1","8.0.0.0b3","8.0.0.0b1","8.0.0.0b2","8.0.0a0","2015.1.0rc1","2015.1.0b3","2015.1.0b2","2015.1.0b1","2014.2.rc1","2014.2.b3","2014.2.b2","2014.2.b1","2014.1.rc1","2014.1.b3","2014.1.b2","2014.1.b1","2013.2.rc1","2013.2.b3","2013.2.b1","grizzly-2","grizzly-1","folsom-rc1","folsom-2","folsom-1","essex-rc1","essex-4","2011.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-12691.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}