cbcvebase.
CVE-2014-0204
published 2014-11-03

CVE-2014-0204: OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote…

medium6.5CVSS 3.1
AVNACLAuSCPIPAP
OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

Affected

7 ranges
VendorProductVersion rangeFixed in
debiankeystone< keystone 2014.1-5 (bookworm)keystone 2014.1-5 (bookworm)
openstackkeystone>= 0 < 2014.1-52014.1-5
openstackkeystone>= 0 < 2014.1-52014.1-5
openstackkeystone>= 0 < 2014.1-52014.1-5
openstackkeystone>= 0 < 2014.1-52014.1-5
openstackkeystone>= 0 < 8.0.0a08.0.0a0
openstackkeystone>= 2014.1 < 2014.1.12014.1.1

CVSS provenance

nvd6.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM