UNKNOWN PyPI

OpenStack Identity Keystone Privilege Escalation vulnerability

GHSA-f889-wfwm-6p7m · CVE-2013-4477 · PYSEC-2026-831

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.

Ready to move

Start Securing

Free, no credit card | First findings in minutes