6.5
CVSSv2

CVE-2014-0204

Published: 03/11/2014 Updated: 02/06/2020
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

OpenStack Identity (Keystone) prior to 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack keystone

Vendor Advisories

Debian Bug report logs - #749026 keystone: CVE-2014-0204: Inproper role assignments to users Package: src:keystone; Maintainer for src:keystone is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 23 May 2014 05:21:01 UTC Severity: important Tags: s ...
OpenStack Identity (Keystone) before 201411 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID ...