CVE-2013-4477
published 2013-11-02CVE-2013-4477: The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to…
PriorityP410low3.3CVSS 2.0
AVLACMAuNCPIPAN
EPSS
0.44%
35.9th percentile
The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2013.2-2 (bookworm) | keystone 2013.2-2 (bookworm) |
| openstack | keystone | >= 0 < 2013.2-2 | 2013.2-2 |
| openstack | keystone | >= 0 < 2013.2-2 | 2013.2-2 |
| openstack | keystone | >= 0 < 2013.2-2 | 2013.2-2 |
| openstack | keystone | >= 0 < 2013.2-2 | 2013.2-2 |
| openstack | keystone | >= 0 < 8.0.0a0 | 8.0.0a0 |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Identity Keystone Privilege Escalation vulnerability
ghsa·2022-05-17
CVE-2013-4477 [LOW] OpenStack Identity Keystone Privilege Escalation vulnerability
OpenStack Identity Keystone Privilege Escalation vulnerability
The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.
OSV
OpenStack Identity Keystone Privilege Escalation vulnerability
osv·2022-05-17
CVE-2013-4477 [LOW] OpenStack Identity Keystone Privilege Escalation vulnerability
OpenStack Identity Keystone Privilege Escalation vulnerability
The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.
OSV
CVE-2013-4477: The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds th
osv·2013-11-02·CVSS 3.3
CVE-2013-4477 [LOW] CVE-2013-4477: The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds th
The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.
Ubuntu
OpenStack Keystone vulnerability
vendor_ubuntu·2013-11-25
CVE-2013-4477 OpenStack Keystone vulnerability
Title: OpenStack Keystone vulnerability
Summary: Keystone would improperly remove roles when it was configured to use the
LDAP backend.
Brant Knudson discovered a logic error in the LDAP backend in Keystone
where removing a role on a tenant for a user who does not have that role
would instead add the role to the user. An authenticated user could use
this to gain privileges. Ubuntu is not configured to use the LDAP Keystone
backend by default.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-keystone: unintentional role granting with Keystone LDAP backend
vendor_redhat·2013-10-21·CVSS 3.3
CVE-2013-4477 [LOW] openstack-keystone: unintentional role granting with Keystone LDAP backend
openstack-keystone: unintentional role granting with Keystone LDAP backend
The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.
Package: openstack-keystone (Red Hat OpenStack Platform 4) - Affected
Debian
CVE-2013-4477: keystone - The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when remov...
vendor_debian·2013·CVSS 3.3
CVE-2013-4477 [LOW] CVE-2013-4477: keystone - The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when remov...
The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.
Scope: local
bookworm: resolved (fixed in 2013.2-2)
bullseye: resolved (fixed in 2013.2-2)
forky: resolved (fixed in 2013.2-2)
sid: resolved (fixed in 2013.2-2)
trixie: resolved (fixed in 2013.2-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4477 openstack-keystone: unintentional role granting with Keystone LDAP backend
bugzilla·2013-10-29·CVSS 3.3
CVE-2013-4477 [LOW] CVE-2013-4477 openstack-keystone: unintentional role granting with Keystone LDAP backend
CVE-2013-4477 openstack-keystone: unintentional role granting with Keystone LDAP backend
The following flaw in Openstack Grizzly and Havana was reported [1],[2]:
The IBM OpenStack test team reported a vulnerability in role change code within the Keystone LDAP backend. When a role on a tenant is removed from a user, and that user doesn't have that role on the tenant, then the user may actually be granted the role on the tenant. A user could use social engineering and leverage that vulnerability to get extra roles granted, or may accidentally be granted extra roles. Only Keystone setups using a LDAP backend are affected.
A CVE has been requested.
[1] https://bugs.launchpad.net/keystone/+bug/1242855
[2] http://seclists.org/oss-sec/2013/q4/186
Discussion:
The Grizzly fix is here:
https:
Bugzilla
CVE-2013-4477 openstack-keystone: unintentional role granting with Keystone LDAP backend [epel-6]
bugzilla·2013-10-29·CVSS 3.3
CVE-2013-4477 [LOW] CVE-2013-4477 openstack-keystone: unintentional role granting with Keystone LDAP backend [epel-6]
CVE-2013-4477 openstack-keystone: unintentional role granting with Keystone LDAP backend [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
ep
Bugzilla
CVE-2013-4477 openstack-keystone: unintentional role granting with Keystone LDAP backend [fedora-all]
bugzilla·2013-10-29·CVSS 3.3
CVE-2013-4477 [LOW] CVE-2013-4477 openstack-keystone: unintentional role granting with Keystone LDAP backend [fedora-all]
CVE-2013-4477 openstack-keystone: unintentional role granting with Keystone LDAP backend [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Ple
http://rhn.redhat.com/errata/RHSA-2014-0113.htmlhttp://www.openwall.com/lists/oss-security/2013/10/30/6http://www.ubuntu.com/usn/USN-2034-1https://bugs.launchpad.net/keystone/+bug/1242855http://rhn.redhat.com/errata/RHSA-2014-0113.htmlhttp://www.openwall.com/lists/oss-security/2013/10/30/6http://www.ubuntu.com/usn/USN-2034-1https://bugs.launchpad.net/keystone/+bug/1242855
2013-11-02
Published