OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade keystone | Jul 30, 2024 | Jun 17, 2014 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.2.0.0.42.0 on Solaris 11.2 | May 29, 2017 | Jun 17, 2014 |
| Ubuntu | — | Upgrade python-keystone | Nov 8, 2024 | Jun 17, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub