CVE-2013-4477

low
Published 2013-11-02 Β· Modified 2024-04-10
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
3.3

Description

The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker Β· View original β†— Β· DFSG

CVE-2013-4477 NameCVE-2013-4477 DescriptionThe LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub…

CVE-2013-4477

NameCVE-2013-4477
DescriptionThe LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs728233

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
keystone (PTS)bullseye2:18.0.0-3+deb11u1fixed
bullseye (security)2:18.1.0-1+deb11u3fixed
bookworm, bookworm (security)2:22.0.2-0+deb12u1fixed
trixie (security), trixie2:27.0.0-3+deb13u1fixed
forky, sid2:29.0.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
keystonesourcewheezy(not affected)
keystonesource(unstable)2013.2-2728233

Notes

[wheezy] - keystone <not-affected> (Vulnerable code not present)
https://bugs.launchpad.net/keystone/+bug/1242855

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[wheezy] - keystone <not-affected> (Vulnerable code not present)https://bugs.launchpad.net/keystone/+bug/1242855

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2013.2-2
sid Fixed 2013.2-2
forky Fixed 2013.2-2
bullseye Fixed 2013.2-2
bookworm Fixed 2013.2-2

Package impact

EcosystemPackageVulnerableFixed
python PyPIkeystone<8.0.0a08.0.0a0

Application impact

VendorProductVersionsFixed
openstackgrizzly-
openstackhavana-

References

CWEs

CWE-264

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.