Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-2673

Опубликовано: 19 июл. 2018
Источник: debian
EPSS Низкий

Описание

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keystonefixed2:10.0.0-9package
keystonenot-affectedjessiepackage
keystonenot-affectedwheezypackage

Примечания

  • https://bugs.launchpad.net/keystone/+bug/1677723

EPSS

Процентиль: 69%
0.00602
Низкий

Связанные уязвимости

CVSS3: 6.8
ubuntu
больше 7 лет назад

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.

CVSS3: 6.8
redhat
почти 9 лет назад

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.

CVSS3: 6.8
nvd
больше 7 лет назад

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.

CVSS3: 7.2
github
больше 3 лет назад

OpenStack Identity service (keystone) Incorrect Authorization

EPSS

Процентиль: 69%
0.00602
Низкий