cbcvebase.
CVE-2014-0204
published 2014-11-03

CVE-2014-0204: OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote…

PriorityP430medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.39%
69.4th percentile
OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

Affected

7 ranges
VendorProductVersion rangeFixed in
debiankeystone< keystone 2014.1-5 (bookworm)keystone 2014.1-5 (bookworm)
openstackkeystone>= 0 < 2014.1-52014.1-5
openstackkeystone>= 0 < 2014.1-52014.1-5
openstackkeystone>= 0 < 2014.1-52014.1-5
openstackkeystone>= 0 < 2014.1-52014.1-5
openstackkeystone>= 0 < 8.0.0a08.0.0a0
openstackkeystone>= 2014.1 < 2014.1.12014.1.1

CVSS provenance

nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.