Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-2673

Опубликовано: 19 июл. 2018
Источник: debian
EPSS Низкий

Описание

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keystonefixed2:10.0.0-9package
keystonenot-affectedjessiepackage
keystonenot-affectedwheezypackage

Примечания

  • https://bugs.launchpad.net/keystone/+bug/1677723

EPSS

Процентиль: 80%
0.02106
Низкий

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 8 лет назад

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.

CVSS3: 6.8
redhat
больше 9 лет назад

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.

CVSS3: 6.8
nvd
около 8 лет назад

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.

CVSS3: 7.2
github
больше 4 лет назад

OpenStack Identity service (keystone) Incorrect Authorization

EPSS

Процентиль: 80%
0.02106
Низкий