openstack-keystone is vulnerable to authorization bypass attacks. The vulnerability exists as OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.
www.openwall.com/lists/oss-security/2013/02/19/3
access.redhat.com/security/updates/classification/#moderate
bugs.launchpad.net/keystone/+bug/1121494
bugzilla.redhat.com/show_bug.cgi?id=908995
launchpad.net/keystone/+milestone/2012.2.4
launchpad.net/keystone/grizzly/2013.1
review.openstack.org/#/c/22319/
review.openstack.org/#/c/22320/
review.openstack.org/#/c/22321/
rhn.redhat.com/errata/RHSA-2013-0596.html