OpenStack Identity Keystone Improper Privilege Management

Description

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

Basic information

Type
reviewed
Severity
medium
Advisory on GitHub
Open advisory ↗
Repository advisory
Source code
Not specified
Published (advisory)
2022-05-13 01:26:10 UTC
Updated
2024-05-14 20:48:54 UTC
GitHub reviewed
2024-05-14 20:48:52 UTC
NVD published
2014-11-03

EPSS Score

Score Percentile
0.35% 57.51%

CVSS Scores

No CVSS scores in this advisory.

Identifiers

CWEs

CWE id Name
CWE-269 Improper Privilege Management

Affected packages (1)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
pip keystone < 8.0.0a0 8.0.0a0

References

cvelogic Threat Intelligence