OpenStack Keystone contains a flaw that is triggered when an account associated with a disabled tenant still authenticates as if the tenant is active. This may allow a user to authenticate in some circumstances where it should not be allowed.
Remote / Network Access
Loss of Integrity
Upgrade to version 2012.1.2 or 2012.2 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.