Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-12690
Python vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2020-12690) was discovered in OpenStack Keystone versions before 15.0.1 and version 16.0.0. The vulnerability was reported by kay and disclosed on May 6, 2020. The issue affects the OAuth1 Token API functionality in OpenStack Keystone (OpenStack OSSA, Ubuntu Security).

Technical details

The vulnerability occurs when the list of roles provided for an OAuth1 access token is silently ignored. When an OAuth1 access token is used to request a keystone token, the keystone token contains every role assignment the creator had for the project instead of the provided subset of roles. This behavior is caused by the token model not properly accounting for OAuth1-scoped tokens and incorrectly populating the roles (OpenStack OSSA).

Impact

The vulnerability results in the provided keystone token having more role assignments than the creator intended, potentially leading to unintended privilege escalation. This could allow users to gain unauthorized elevated access to project resources (OpenStack OSSA, Ubuntu Security).

Exploitability

The vulnerability requires an authenticated user with access to OAuth1 token functionality. The exploitation is limited to trusted users who need permissions to issue an OAuth1 token (OSS Security).

Mitigation and workarounds

For affected versions, users can either upgrade to Keystone version 15.0.1 or later (except 16.0.0), or implement temporary mitigations. Temporary mitigations include disabling OAuth1 as an authentication method by removing it from the [auth]/methods config option in keystone.conf, or restricting access by disabling specific policy rules such as 'identity:create_consumer', 'identity:update_consumer', and 'identity:authorize_request_token' (OSS Security).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-66455CRITICAL9.8
  • Python logoPython
  • lmdeploy
NoYesSep 18, 2026
CVE-2026-63374CRITICAL9.3
  • Python logoPython
  • airflow-core-2
NoYesSep 18, 2026
CVE-2026-59163CRITICAL9.1
  • Python logoPython
  • mnemosyne-memory
NoYesSep 18, 2026
CVE-2026-33625HIGH8.8
  • Python logoPython
  • lmdeploy
NoYesSep 18, 2026
CVE-2026-64847MEDIUM6.8
  • Python logoPython
  • airflow-3
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management