PT-2013-5034 · Openstack · Openstack Identity
Blk-U
+1
·
Publicado
2013-11-02
·
Atualizado
2022-05-17
·
CVE-2013-4477
CVSS v2.0
3.3
Baixa
| Vetor | AV:L/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Identity (Keystone) versions Grizzly through Havana
Description
The issue in OpenStack Identity (Keystone) allows local users to gain privileges by adding a role to a user when removing a role on a tenant for a user who does not have that role.
Recommendations
For OpenStack Identity (Keystone) versions Grizzly through Havana, consider restricting access to the LDAP backend until a fix is available. As a temporary workaround, manually review and correct user roles after removal to prevent unintended privilege escalation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openstack Identity