Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-0204

Опубликовано: 03 нояб. 2014
Источник: nvd
CVSS2: 6.5
EPSS Низкий

Описание

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
Версия от 2014.1 (включая) до 2014.1.1 (исключая)

EPSS

Процентиль: 57%
0.00353
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-269

Связанные уязвимости

ubuntu
больше 11 лет назад

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

redhat
больше 11 лет назад

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

debian
больше 11 лет назад

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle ...

github
больше 3 лет назад

OpenStack Identity Keystone Improper Privilege Management

EPSS

Процентиль: 57%
0.00353
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-269