VDB
KO
HIGH 7.2

PYSEC-2018-152

Details

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / keystone
Introduced in: 9.0.0

No fixed version published yet for keystone (pip). Pin to a known-safe version or switch to an alternative.

PyPI / keystone
Introduced in: 10.0.0 Fixed in: 10.0.2
Fix pip install --upgrade 'keystone>=10.0.2'
PyPI / keystone
Introduced in: 11.0.0 Fixed in: 11.0.1
Fix pip install --upgrade 'keystone>=11.0.1'

References