CVE-2013-4477 - CERT CVE
ID CVE-2013-4477
Sažetak The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.
Reference
CVSS
Base: 3.3
Impact: 4.9
Exploitability:3.4
Pristup
VektorSloženostAutentikacija
LOCAL MEDIUM NONE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL PARTIAL NONE
CVSS vektor AV:L/AC:M/Au:N/C:P/I:P/A:N
Zadnje važnije ažuriranje 06-03-2014 - 04:47
Objavljeno 02-11-2013 - 19:55