VDB
Sign up
HIGH7.2

PYSEC-2018-152

Quick fix

PYSEC-2018-152 — keystone: upgrade to the fixed version with the command below.

pip install --upgrade 'keystone>=10.0.2'

Details

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/keystone
Introduced in: 9.0.0Fixed in: 10.0.2
Fixpip install --upgrade 'keystone>=10.0.2'

References