CVE-2013-4477
Publication date 2 November 2013
Last updated 24 July 2024
Ubuntu priority
The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.
Status
Package | Ubuntu Release | Status |
---|---|---|
keystone | 13.10 saucy |
Fixed 1:2013.2-0ubuntu1.1
|
13.04 raring |
Fixed 1:2013.1.4-0ubuntu1.1
|
|
12.10 quantal |
Fixed 2012.2.4-0ubuntu3.3
|
|
12.04 LTS precise |
Not affected
|
|
10.04 LTS lucid | Not in release |
Patch details
Package | Patch details |
---|---|
keystone |
|
References
Related Ubuntu Security Notices (USN)
- USN-2034-1
- OpenStack Keystone vulnerability
- 25 November 2013