Bug 876902 (CVE-2014-0204) - VUL-0: CVE-2014-0204: openstack-keystone: Inproper role assignments to users
Summary: VUL-0: CVE-2014-0204: openstack-keystone: Inproper role assignments to users
Status: RESOLVED FIXED
Alias: CVE-2014-0204
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-05-08 15:06 UTC by Johannes Segitz
Modified: 2016-04-27 19:29 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2014-05-08 15:06:49 UTC
Created attachment 589197 [details]
Patch for CVE-2014-0204

Via distros (Message-ID: <536B961B.2030009@enovance.com>)

EMBARGOED: yes (2014-05-20, 1500UTC)

Michael Stancampiano from IBM reported a vulnerability in Keystone.
Someone with write access to the user and group repository (such as the
LDAP directory server) may willingly or unwillingly grant additional
rights by picking the same IDs for users and groups, resulting in roles
assigned to a group being assigned to the affected user even if he is
not a member of this group. Only Keystone setups using LDAP for the
Identity driver are affected.

Versions affected: 2014.1
There could be other versions affected, the post isn't absolutely clear about that.
Comment 1 Swamp Workflow Management 2014-05-08 22:00:30 UTC
bugbot adjusting priority
Comment 3 Johannes Segitz 2014-05-22 09:14:13 UTC
So this probably affects openSUSE:Factory and Cloud4. I suggest that we release this with the next Cloud update
Comment 4 SMASH SMASH 2014-05-22 09:15:16 UTC
Affected packages:

SLE-11-SP3-CLOUD4: openstack-keystone
Comment 6 Vincent Untz 2014-08-19 07:00:43 UTC
The fix was part of Cloud 4 GM.