OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated May 14, 2024
Description
Published by the National Vulnerability Database
Jun 17, 2014
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
May 14, 2024
Last updated
May 14, 2024
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.
References