HIGH7.2
PYSEC-2018-152
Quick fix
PYSEC-2018-152 — keystone: upgrade to the fixed version with the command below.
pip install --upgrade 'keystone>=10.0.2'Details
An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2673[REPORT]
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2673[FIX]
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2673[ADVISORY]
- https://bugs.launchpad.net/keystone/+bug/1677723[EVIDENCE]
- https://bugs.launchpad.net/keystone/+bug/1677723[FIX]
- https://bugs.launchpad.net/keystone/+bug/1677723[WEB]
- http://seclists.org/oss-sec/2017/q2/125[ARTICLE]
- http://seclists.org/oss-sec/2017/q2/125[FIX]
- http://seclists.org/oss-sec/2017/q2/125[WEB]
- https://access.redhat.com/errata/RHSA-2017:1597[ADVISORY]
- https://access.redhat.com/errata/RHSA-2017:1461[ADVISORY]
- http://www.securityfocus.com/bid/98032[WEB]
- http://www.securityfocus.com/bid/98032[ADVISORY]