OpenStack Keystone User and Group ID Mismatch Security Bypass Vulnerability
BID:67580
Info
OpenStack Keystone User and Group ID Mismatch Security Bypass Vulnerability
| Bugtraq ID: | 67580 |
| Class: | Design Error |
| CVE: |
CVE-2014-0204 |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2014 12:00AM |
| Updated: | May 21 2014 12:00AM |
| Credit: | Michael Stancampiano from IBM |
| Vulnerable: |
OpenStack Keystone 2014.1 |
| Not Vulnerable: |
OpenStack Keystone 2014.1.1 |
Solution / Fix
OpenStack Keystone User and Group ID Mismatch Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OpenStack Keystone User and Group ID Mismatch Security Bypass Vulnerability
References:
References:
- [OSSA 2014-015] Keystone user and group id mismatch (CVE-2014-0204) (Tristan Cacqueray)
- LDAP fix for get_roles_for_user_and_project user=group ID (Brant Knudson)
- OpenStack Keystone Homepage (OpenStack )
- SQL and LDAP fixes for get_roles_for_user_and_project user=group ID (Brant Knudson)
- SQL fix for get_roles_for_user_and_project user=group ID (Brant Knudson)