Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-2673

Опубликовано: 19 июл. 2018
Источник: nvd
CVSS3: 6.8
CVSS3: 7.2
CVSS2: 6.5
EPSS Низкий

Описание

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:openstack:9:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*

EPSS

Процентиль: 68%
0.00572
Низкий

6.8 Medium

CVSS3

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-863
CWE-863

Связанные уязвимости

CVSS3: 6.8
ubuntu
больше 7 лет назад

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.

CVSS3: 6.8
redhat
почти 9 лет назад

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.

CVSS3: 6.8
debian
больше 7 лет назад

An authorization-check flaw was discovered in federation configuration ...

CVSS3: 7.2
github
больше 3 лет назад

OpenStack Identity service (keystone) Incorrect Authorization

EPSS

Процентиль: 68%
0.00572
Низкий

6.8 Medium

CVSS3

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-863
CWE-863