Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c4p9-87h3-7vr4

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

OpenStack Identity Keystone Improper Privilege Management

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

Пакеты

Наименование

keystone

pip
Затронутые версииВерсия исправления

< 8.0.0a0

8.0.0a0

EPSS

Процентиль: 57%
0.00353
Низкий

Дефекты

CWE-269

Связанные уязвимости

ubuntu
больше 11 лет назад

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

redhat
больше 11 лет назад

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

nvd
больше 11 лет назад

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

debian
больше 11 лет назад

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle ...

EPSS

Процентиль: 57%
0.00353
Низкий

Дефекты

CWE-269