CVE-2014-0204

Severity

65%

Complexity

80%

Confidentiality

106%

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

CVSS 2.0 Base Score 6.5. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P).

Overview

First reported 10 years ago

2014-11-03 23:55:00

Last updated 10 years ago

2014-11-04 21:30:00

Affected Software

OpenStack Keystone 2012.1

2012.1

OpenStack Keystone 2012.1.1

2012.1.1

OpenStack Keystone 2012.1.2

2012.1.2

OpenStack Keystone 2012.1.3

2012.1.3

OpenStack Keystone 2012.2

2012.2

OpenStack Keystone 2012.2.1

2012.2.1

OpenStack Keystone 2012.2.2

2012.2.2

OpenStack Keystone 2012.2.3

2012.2.3

OpenStack Keystone 2012.2.4

2012.2.4

OpenStack Keystone 2013

2013

OpenStack Keystone (Grizzly) 2013.1

2013.1

OpenStack Keystone 2013.1.1

2013.1.1

OpenStack Keystone 2013.1.2

2013.1.2

OpenStack Keystone 2013.1.3

2013.1.3

OpenStack Keystone 2013.1.4

2013.1.4

OpenStack Keystone 2013.2

2013.2

OpenStack Keystone 2013.2.1

2013.2.1

OpenStack Keystone 2013.2.2

2013.2.2

OpenStack Keystone 2013.2.3

2013.2.3

OpenStack Keystone 2013.2.4

2013.2.4

OpenStack Keystone

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.