OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade keystone | Jul 30, 2024 | Apr 12, 2013 |
| Suse | — | Upgrade openstack-swift-containerUpgrade openstack-swift-docUpgrade openstack-cinder-testUpgrade python-cinderclientUpgrade openstack-dashboardUpgrade openstack-swift-objectUpgrade python-quantumUpgrade openstack-nova-volumeUpgrade openstack-novaUpgrade python-django_openstack_authUpgrade openstack-swift-proxyUpgrade python-keystoneUpgrade openstack-nova-computeUpgrade openstack-nova-testUpgrade openstack-nova-novncproxyUpgrade openstack-keystoneUpgrade openstack-quantum-testUpgrade openstack-swiftUpgrade openstack-keystone-testUpgrade openstack-swift-accountUpgrade python-swiftUpgrade openstack-dashboard-testUpgrade openstack-nova-vncproxyUpgrade python-cinderUpgrade openstack-nova-certUpgrade openstack-cinder-apiUpgrade openstack-nova-schedulerUpgrade openstack-glance-testUpgrade python-keystoneclient-docUpgrade openstack-nova-networkUpgrade openstack-glance-docUpgrade openstack-quantum-docUpgrade python-cinderclient-docUpgrade openstack-cinderUpgrade openstack-cinder-schedulerUpgrade openstack-quantumUpgrade openstack-nova-docUpgrade openstack-nova-apiUpgrade openstack-glanceUpgrade python-keystoneclientUpgrade python-novaUpgrade python-keystoneclient-testUpgrade openstack-cinder-docUpgrade openstack-nova-objectstoreUpgrade openstack-cinder-volumeUpgrade python-glanceUpgrade openstack-swift-testUpgrade python-cinderclient-testUpgrade python-horizonUpgrade openstack-quickstartUpgrade openstack-keystone-doc | Dec 12, 2013 | Apr 12, 2013 |
| Ubuntu | — | Upgrade python-keystone | Nov 8, 2024 | Apr 12, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub