Privilege Escalation The advisory has been revoked - it doesn't affect any version of package keystone  (opens in a new tab)


Threat Intelligence

EPSS
0.04% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-KEYSTONE-40020
  • published30 Oct 2013
  • disclosed30 Oct 2013
  • creditUnknown

Introduced: 30 Oct 2013

CVE-2013-4477  (opens in a new tab)
CWE-264  (opens in a new tab)

Amendment

This was deemed not a vulnerability.

Overview

keystone is a package that provides authentication, authorization and service discovery mechanisms via HTTP primarily for use by projects in the OpenStack family.

Affected versions of this package are vulnerable to Privilege Escalation. The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.

References