CVE-2014-0204
OpenStack Identity Keystone Improper Privilege Management
EPSS 1.4%
描述
OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.
如何修補 CVE-2014-0204
要修補 CVE-2014-0204,請將受影響套件升級到下列已修補版本。
- PyPI/keystone—升級至 8.0.0a0 或更新版本
- PyPI/keystone—升級至 8.0.0a0 或更新版本
CVE-2014-0204 正在被利用嗎?
低 — EPSS 為 1.4%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 8.0.0a0
- from 0, < 8.0.0a0