Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0204

Опубликовано: 21 мая 2014
Источник: redhat
CVSS2: 2.7

Описание

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

Отчет

Not vulnerable. This issue did not affect the versions of openstack-keystone as shipped with Red Hat Enterprise Linux OpenStack Platform 3 and 4.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 3openstack-keystoneNot affected
Red Hat OpenStack Platform 4openstack-keystoneNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1095981openstack-keystone: user and group id mismatch

2.7 Low

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

nvd
больше 11 лет назад

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

debian
больше 11 лет назад

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle ...

github
больше 3 лет назад

OpenStack Identity Keystone Improper Privilege Management

2.7 Low

CVSS2