[openstack-announce] [OSSA 2014-015] Keystone user and group id mismatch (CVE-2014-0204)

Tristan Cacqueray tristan.cacqueray at enovance.com
Wed May 21 19:56:54 UTC 2014


OpenStack Security Advisory: 2014-015
CVE: CVE-2014-0204
Date: May 21, 2014
Title: Keystone user and group id mismatch
Reporter: Michael Stancampiano (IBM)
Products: Keystone
Versions: 2014.1

Description:
Michael Stancampiano from IBM reported a vulnerability in Keystone.
Someone with write access to the user and group repository (such as the
LDAP directory server) may willingly or unwillingly grant additional
rights by picking the same IDs for users and groups, resulting in roles
assigned to a group being assigned to the affected user even if he is
not a member of this group. Only Keystone setups using LDAP for the
Identity driver are affected.

Juno (development branch) fixes:
https://review.openstack.org/94396
https://review.openstack.org/94470

Icehouse fix:
https://review.openstack.org/94397

Notes:
This fix will be included in the juno-1 development milestone and in
a future 2014.1.1 release.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0204
https://launchpad.net/bugs/1309228

-- 
Tristan Cacqueray
OpenStack Vulnerability Management Team



-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 555 bytes
Desc: OpenPGP digital signature
URL: <http://lists.openstack.org/pipermail/openstack-announce/attachments/20140521/ed898858/attachment.pgp>


More information about the OpenStack-announce mailing list