UNKNOWN PyPI

OpenStack Identity Keystone Improper Privilege Management

GHSA-c4p9-87h3-7vr4 · CVE-2014-0204 · PYSEC-2026-654

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

Ready to move

Start Securing

Free, no credit card | First findings in minutes