Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-2673

Опубликовано: 25 апр. 2017
Источник: redhat
CVSS3: 6.8

Описание

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)openstack-keystoneNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)openstack-keystoneNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)openstack-keystoneNot affected
Red Hat OpenStack Platform 11 (Ocata)openstack-keystoneAffected
Red Hat OpenStack Platform 8 (Liberty)openstack-keystoneNot affected
Red Hat OpenStack Platform 10.0 (Newton)openstack-keystoneFixedRHSA-2017:159728.06.2017
Red Hat OpenStack Platform 9.0 (Mitaka)openstack-keystoneFixedRHSA-2017:146114.06.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1439586openstack-keystone: Incorrect role assignment with federated Keystone

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
ubuntu
больше 7 лет назад

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.

CVSS3: 6.8
nvd
больше 7 лет назад

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.

CVSS3: 6.8
debian
больше 7 лет назад

An authorization-check flaw was discovered in federation configuration ...

CVSS3: 7.2
github
больше 3 лет назад

OpenStack Identity service (keystone) Incorrect Authorization

6.8 Medium

CVSS3