CVE-2014-0204
published 2014-11-03CVE-2014-0204: OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote…
PriorityP430medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.39%
69.4th percentile
OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2014.1-5 (bookworm) | keystone 2014.1-5 (bookworm) |
| openstack | keystone | >= 0 < 2014.1-5 | 2014.1-5 |
| openstack | keystone | >= 0 < 2014.1-5 | 2014.1-5 |
| openstack | keystone | >= 0 < 2014.1-5 | 2014.1-5 |
| openstack | keystone | >= 0 < 2014.1-5 | 2014.1-5 |
| openstack | keystone | >= 0 < 8.0.0a0 | 8.0.0a0 |
| openstack | keystone | >= 2014.1 < 2014.1.1 | 2014.1.1 |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-keystone: user and group id mismatch
vendor_redhat·2014-05-21·CVSS 6.5
CVE-2014-0204 [MEDIUM] openstack-keystone: user and group id mismatch
openstack-keystone: user and group id mismatch
OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.
Statement: Not vulnerable. This issue did not affect the versions of openstack-keystone as shipped with Red Hat Enterprise Linux OpenStack Platform 3 and 4.
Package: openstack-keystone (Red Hat OpenStack Platform 3) - Not affected
Package: openstack-keystone (Red Hat OpenStack Platform 4) - Not affected
Debian
CVE-2014-0204: keystone - OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a ro...
vendor_debian·2014·CVSS 6.5
CVE-2014-0204 [MEDIUM] CVE-2014-0204: keystone - OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a ro...
OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.
Scope: local
bookworm: resolved (fixed in 2014.1-5)
bullseye: resolved (fixed in 2014.1-5)
forky: resolved (fixed in 2014.1-5)
sid: resolved (fixed in 2014.1-5)
trixie: resolved (fixed in 2014.1-5)
Cisco
Multiple Vulnerabilities in OpenSSL (January 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-0204 Multiple Vulnerabilities in OpenSSL (January 2015) Affecting Cisco Products
CVE-2015-0204: Multiple Vulnerabilities in OpenSSL (January 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service condition or perform a man-in-the-middle attack. On January 8, 2015, the OpenSSL Project released a security advisory detailing eight distinct vulnerabilities. The vulnerabilities are referenced in this document as follows: CVE-2014-3571: OpenSSL DTLS Message Processing Denial of Service Vulnerability CVE-2015-0206: OpenSSL dtls1_buffer_record Function DTLS Message Processing Denial of Service Vulnerability CVE-2014-3569: OpenSSL no-ssl3 Option NULL Pointer Dereference Vulnerability CVE-2014-3572: OpenSSL Ellipti
OSV
OpenStack Identity Keystone Improper Privilege Management
osv·2022-05-13
CVE-2014-0204 [MEDIUM] OpenStack Identity Keystone Improper Privilege Management
OpenStack Identity Keystone Improper Privilege Management
OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.
GHSA
OpenStack Identity Keystone Improper Privilege Management
ghsa·2022-05-13
CVE-2014-0204 [MEDIUM] CWE-269 OpenStack Identity Keystone Improper Privilege Management
OpenStack Identity Keystone Improper Privilege Management
OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.
OSV
CVE-2014-0204: OpenStack Identity (Keystone) before 2014
osv·2014-11-03·CVSS 6.5
CVE-2014-0204 [MEDIUM] CVE-2014-0204: OpenStack Identity (Keystone) before 2014
OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0204 openstack-keystone: user and group id mismatch [fedora-all]
bugzilla·2014-05-25·CVSS 6.5
CVE-2014-0204 [MEDIUM] CVE-2014-0204 openstack-keystone: user and group id mismatch [fedora-all]
CVE-2014-0204 openstack-keystone: user and group id mismatch [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2014-0204 openstack-keystone: user and group id mismatch
bugzilla·2014-05-09·CVSS 6.5
CVE-2014-0204 [MEDIUM] CVE-2014-0204 openstack-keystone: user and group id mismatch
CVE-2014-0204 openstack-keystone: user and group id mismatch
The OpenStack project reports:
""
Title: Keystone user and group id mismatch
Reporter: Michael Stancampiano (IBM)
Products: Keystone
Versions: 2014.1
Description:
Michael Stancampiano from IBM reported a vulnerability in Keystone.
Someone with write access to the user and group repository (such as the
LDAP directory server) may willingly or unwillingly grant additional
rights by picking the same IDs for users and groups, resulting in roles
assigned to a group being assigned to the affected user even if he is
not a member of this group. Only Keystone setups using LDAP for the
Identity driver are affected.
""
Acknowledgements:
Red Hat would like to thank the Openstack project for reporting this issue. Upstream acknowledges Mic
Bugzilla
CVE-2014-0058 Red Hat JBoss EAP6: Plain text password logging during security audit
bugzilla·2014-02-11·CVSS 1.9
CVE-2014-0058 [LOW] CVE-2014-0058 Red Hat JBoss EAP6: Plain text password logging during security audit
CVE-2014-0058 Red Hat JBoss EAP6: Plain text password logging during security audit
It was identified that web auditing, as provided by Red Hat JBoss Enterprise Application Platform 6, logged request parameters in plain text. This may include passwords used for authentication mechanisms such as BASIC and FORMAUTH. A local attacker, with access to audit logs, could compromise application/server credentials.
Discussion:
This issue has been addressed in following products:
Red Hat JBoss Enterprise Application Platform 6.2.1
Via RHSA-2014:0205 https://rhn.redhat.com/errata/RHSA-2014-0205.html
---
This issue has been addressed in following products:
JBEAP 6.2 for RHEL 5
JBEAP 6.2 for RHEL 6
Via RHSA-2014:0204 https://rhn.redhat.com/errata/RHSA-2014-0204.html
---
This issue has been a
2014-11-03
Published