Beveiligingsadvies

CVE-2017-2673

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2018-07-19 13:00:00
Laatst bijgewerkt 2024-08-05 14:02:07
Toegewezen door redhat
CVSS-score 6.8
Status PUBLISHED

Beschrijving

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.