The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.
2013-11-02T19:55:04.773
2025-04-11T00:51:21.963
Deferred
CVSSv2: 3.3 (LOW)
AV:L/AC:M/Au:N/C:P/I:P/A:N
3.4
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openstack | grizzly | - | Yes |
Application | openstack | havana | - | Yes |