OpenStack Identity Keystone Improper Privilege Management
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated May 14, 2024
Description
Published by the National Vulnerability Database
Nov 3, 2014
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
May 14, 2024
Last updated
May 14, 2024
OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.
References